漏洞信息详情
Chipmailer php.php直接请求 信息泄露漏洞
漏洞简介
Chipmailer 1.09可以使远程攻击者借助对php.php的直接请求,显示phpinfo函数的输出,从而获得敏感信息。
漏洞公告
目前厂商已经发布了相关补丁,请到厂商的主页下载:
TWiki TWiki 4.0
TWiki Twiki Patch (diff file) for versions 4.0.0, 4.0.1, and 4.0.2
http://twiki.org/p/pub/Codev/SecurityAlertTWiki4PrivilegeElevation/CVE -2006-2942-hotfix-4.0.0-4.0.2.diff
TWiki TWiki 4.0.1
TWiki Twiki Patch (diff file) for versions 4.0.0, 4.0.1, and 4.0.2
http://twiki.org/p/pub/Codev/SecurityAlertTWiki4PrivilegeElevation/CVE -2006-2942-hotfix-4.0.0-4.0.2.diff
TWiki TWiki 4.0.2
TWiki Twiki Patch (diff file) for versions 4.0.0, 4.0.1, and 4.0.2
http://twiki.org/p/pub/Codev/SecurityAlertTWiki4PrivilegeElevation/CVE -2006-2942-hotfix-4.0.0-4.0.2.diff
参考网址
来源: SECTRACK
名称: 1016315
链接:http://securitytracker.com/id?1016315
来源: BUGTRAQ
名称: 20060613 Chipmailer
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=115024576618386&w=2
来源: XF
名称: chipmailer-php-information-disclosure(27159)
链接:http://xforce.iss.net/xforce/xfdb/27159
受影响实体
- Chipmailer Chipmailer:1.09<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...