Grayscale BandSite CMS 多个输入验证漏洞 CVE-2006-4986 CNNVD-200609-432

5.0 AV AC AU C I A
发布: 2006-09-26
修订: 2018-10-17

Grayscale BandSite CMS可让远程攻击者通过直接请求以下文件,在各种错误消息中揭示路径,从而获取敏感信息:(1)includes/content目录中的某些文件,(2)includes/shows_preview.php和(3)adminpanel/configform.php;以及adminpanel/includes/中的文件,包括(4) mailinglist/disphtmltbl.php、(5)mailinglist/dispxls.php、(6)mailinglist/sendshows.php、(7)previews/preview_bio.php、(8) previews/preview_genmerch.php、(9)previews/preview_fliers.php、(10) previews/preview_gbook.php、(11)previews/preview_interviews.php、(12)previews/preview_links.php、(13)previews/preview_lyrics.php、(14)previews/preview_membio.php、(15) previews/preview_merchphotos.php、(16)previews/preview_mp3s.php、(17)previews/preview_news.php、(18)previews/preview_photos.php、(19) previews/preview_releases.php、(20)previews/preview_relmerch.php、(21)previews/preview_relphotos.php、(22)...

0%
暂无可用Exp或PoC
当前有1条受影响产品信息