BlackBoard Internet Newsboard System远程文件列入漏洞

漏洞信息详情

BlackBoard Internet Newsboard System远程文件列入漏洞

漏洞简介

BlackBoard 1.5.1版本存在PHP远程文件列入漏洞。远程攻击者通过修改libpath参数(incorrectly called \”libpach\”)参考包含_more.php的远程web服务器上的URL执行任意PHP代码,比如使用checkdb.inc.php。

漏洞公告

The vendor has released a patch to address this issue:
BlackBoard Internet Newsboard System BlackBoard Internet Newsboard System 1.5.1

参考网址

来源: XF
名称: blackboard-lang-file-include(17637)
链接:http://xforce.iss.net/xforce/xfdb/17637

来源: BID
名称: 11336
链接:http://www.securityfocus.com/bid/11336

来源: SECUNIA
名称: 12757
链接:http://secunia.com/advisories/12757

来源: blackboard.unclassified.de
链接:http://blackboard.unclassified.de/70,1#1031

来源: BUGTRAQ
名称: 20041006 Multiple vulnerabilities in BlackBoard
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109707701719659&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享