在线书签认证绕过漏洞

漏洞信息详情

在线书签认证绕过漏洞

漏洞简介

Online-bookmarks 0.4.6之前的版本存在漏洞。远程攻击者借助(1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php,或(6) functions.php的直接请求绕过它的认证机制。

漏洞公告

The vendor has made online-bookmarks 0.4.6 available. Please see the references for details.
online-bookmarks Web Based Bookmark Application 0.4

online-bookmarks Web Based Bookmark Application 0.4.2

online-bookmarks Web Based Bookmark Application 0.4.4

参考网址

来源: XF
名称: online-bookmarks-resrtictions-bypass(17602)
链接:http://xforce.iss.net/xforce/xfdb/17602

来源: BID
名称: 11305
链接:http://www.securityfocus.com/bid/11305

来源: SECUNIA
名称: 12728
链接:http://secunia.com/advisories/12728/

来源: freshmeat.net
链接:http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&release_id=174401

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享