网站地图    收藏   

主页 > 后端 > 网站安全 >

Dolibarr CMS v3.2.0 Alpha文件包含及修复 - 网站安全

来源:自学PHP网    时间:2015-04-17 13:03 作者: 阅读:

[导读] 标题Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities概述:Dolibarr ERP CRM is a modern software to manage your company or foundation activity (contacts, suppliers,......

标题Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities
概述:Dolibarr ERP & CRM is a modern software to manage your company or foundation activity (contacts, suppliers,
invoices, orders, stocks, agenda, ...). It s an opensource free software designed for small and medium
companies, foundations and freelances. You can install, use and distribute it as a standalone application
or as a web application (on mutualized or dedicated server, or on SaaS or Cloud solutions) and use it with
any devices (desktop, smartphone, tablet).

开发网站: http://www.dolibarr.org

摘要:
安全研究员在 Dolibarrs CMS v3.2.0 Alpha发现一个包含漏洞

状态:Published

分析:
Multiple File Include Vulnerabilities are detected on Dolibarrs Content Management System v3.2.0 Alpha.
The vulnerability allows an attacker (remote) or local low privileged user account to request local web-server
or system files.  Successful exploitation of the vulnerability results in dbms & application compromise.
Vulnerable Module(s):
                    [+] ?modulepart=project&file=
                    [+] ?action=create&actioncode=AC_RDV&contactid=1&socid=1&backtopage=
Picture(s):
                    ../1.png
                    ../2.png
测试证明t:
=================
The vulnerabilities can be exploited by remote attackers or local low privileged user accounts. For demonstration or reproduce ...
http://www.2cto.com /document.php?modulepart=project&file=../[FILE INCLUDE VULNERABILITY!]
http://www.2cto.com /comm/action/fiche.php?action=create&actioncode=AC_RDV&contactid=1&socid=1&backtopage=../common/[FILE INCLUDE VULNERABILITY!]
风险等级:
=====
The security riks of the file include vulnerabilities are estimated as high(+).

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论