来源:自学PHP网 时间:2015-04-17 13:03 作者: 阅读:次
[导读] 标题Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities概述:Dolibarr ERP CRM is a modern software to manage your company or foundation activity (contacts, suppliers,......
标题Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities
概述:Dolibarr ERP & CRM is a modern software to manage your company or foundation activity (contacts, suppliers, invoices, orders, stocks, agenda, ...). It s an opensource free software designed for small and medium companies, foundations and freelances. You can install, use and distribute it as a standalone application or as a web application (on mutualized or dedicated server, or on SaaS or Cloud solutions) and use it with any devices (desktop, smartphone, tablet). 开发网站: http://www.dolibarr.org 摘要: 安全研究员在 Dolibarrs CMS v3.2.0 Alpha发现一个包含漏洞 状态:Published 分析: Multiple File Include Vulnerabilities are detected on Dolibarrs Content Management System v3.2.0 Alpha. The vulnerability allows an attacker (remote) or local low privileged user account to request local web-server or system files. Successful exploitation of the vulnerability results in dbms & application compromise. Vulnerable Module(s): [+] ?modulepart=project&file= [+] ?action=create&actioncode=AC_RDV&contactid=1&socid=1&backtopage= Picture(s): ../1.png ../2.png 测试证明t: ================= The vulnerabilities can be exploited by remote attackers or local low privileged user accounts. For demonstration or reproduce ... http://www.2cto.com /document.php?modulepart=project&file=../[FILE INCLUDE VULNERABILITY!] http://www.2cto.com /comm/action/fiche.php?action=create&actioncode=AC_RDV&contactid=1&socid=1&backtopage=../common/[FILE INCLUDE VULNERABILITY!] 风险等级: ===== The security riks of the file include vulnerabilities are estimated as high(+). |
自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习
京ICP备14009008号-1@版权所有www.zixuephp.com
网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com