漏洞信息详情
Grayscale BandSite CMS 多个输入验证漏洞
- CNNVD编号:CNNVD-200609-432
- 危害等级: 中危
![图片[1]-Grayscale BandSite CMS 多个输入验证漏洞-一一网](https://www.proyy.com/skycj/data/images/2021-04-27/30f462579bec41fc25e0b1d57503e6d6.png)
- CVE编号:
CVE-2006-4986
- 漏洞类型:
输入验证
- 发布时间:
2006-09-25
- 威胁类型:
远程
- 更新时间:
2006-10-18
- 厂 商:
grayscale - 漏洞来源:
HACKERS PAL is cre… -
漏洞简介
Grayscale BandSite CMS可让远程攻击者通过直接请求以下文件,在各种错误消息中揭示路径,从而获取敏感信息:(1)includes/content目录中的某些文件,(2)includes/shows_preview.php和(3)adminpanel/configform.php;以及adminpanel/includes/中的文件,包括(4) mailinglist/disphtmltbl.php、(5)mailinglist/dispxls.php、(6)mailinglist/sendshows.php、(7)previews/preview_bio.php、(8) previews/preview_genmerch.php、(9)previews/preview_fliers.php、(10) previews/preview_gbook.php、(11)previews/preview_interviews.php、(12)previews/preview_links.php、(13)previews/preview_lyrics.php、(14)previews/preview_membio.php、(15) previews/preview_merchphotos.php、(16)previews/preview_mp3s.php、(17)previews/preview_news.php、(18)previews/preview_photos.php、(19) previews/preview_releases.php、(20)previews/preview_relmerch.php、(21)previews/preview_relphotos.php、(22) previews/preview_reviews.php、(23)previews/preview_shows.php、(24)previews/preview_wearmerch.php、(25)change_forms/change_bio.php、(26)change_forms/change_fliers.php、(27)change_forms/change_gbook.php、(28)change_forms/change_gen_merch.php、(29) change_forms/change_interview.php、(30)change_forms/change_links.php、(31)change_forms/change_lyrics.php、(32) change_forms/change_members.php、(33)change_forms/change_merch.php、(34)change_forms/change_merch_pic.php、(35) change_forms/change_mp3s.php、(36)change_forms/change_news.php、(37)change_forms/change_photos.php、(38) change_forms/change_rel_merch.php、(39)change_forms/change_rel_pic.php、(40)change_forms/change_releases.php、(41) change_forms/change_reviews.php、(42)change_forms/change_shows.php和(43) change_forms/change_wear_merch.php。
漏洞公告
参考网址
来源: BID
名称: 20137
链接:http://www.securityfocus.com/bid/20137
来源: BUGTRAQ
名称: 20060921 Grayscale BandSite CMS Multiple Input Validation Vulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/446576/100/0/threaded
来源: XF
名称: grayscale-bandsite-information-disclosure(29085)
链接:http://xforce.iss.net/xforce/xfdb/29085
来源: SREASON
名称: 1634





















![[桜井宁宁]COS和泉纱雾超可爱写真福利集-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/4d3cf227a85d7e79f5d6b4efb6bde3e8.jpg)

![[桜井宁宁] 爆乳奶牛少女cos写真-一一网](https://www.proyy.com/skycj/data/images/2020-12-13/d40483e126fcf567894e89c65eaca655.jpg)