漏洞信息详情
Serendipity 多个目录遍访漏洞
- CNNVD编号:CNNVD-200612-018
- 危害等级: 中危
- CVE编号:
CVE-2006-6242
- 漏洞类型:
路径遍历
- 发布时间:
2006-12-03
- 威胁类型:
远程
- 更新时间:
2006-12-05
- 厂 商:
s9y - 漏洞来源:
Kacper is credited… -
漏洞简介
Serendipity存在多个目录遍访漏洞,远程攻击者可通过在(1)include/lang.inc.php内;或传给plugins/ scripts(2)serendipity_event_bbcode/serendipity_event_bbcode.php,(3)serendipity_event_browsercompatibility/serendipity_event_browsercompatibility.php,(4)serendipity_event_contentrewrite/serendipity_event_contentrewrite.php,(5)serendipity_event_creativecommons/serendipity_event_creativecommons.php,(6)serendipity_event_emoticate/serendipity_event_emoticate.php,(7)serendipity_event_entryproperties/serendipity_event_entryproperties.php,(8)serendipity_event_karma/serendipity_event_karma.php,(9)serendipity_event_livesearch/serendipity_event_livesearch.php,(10)serendipity_event_mailer/serendipity_event_mailer.php,(11)serendipity_event_nl2br/serendipity_event_nl2br.php,(12)serendipity_event_s9ymarkup/serendipity_event_s9ymarkup.php,(13)serendipity_event_searchhighlight/serendipity_event_searchhighlight.php,(14)serendipity_event_spamblock/serendipity_event_spamblock.php,(15)serendipity_event_spartacus/serendipity_event_spartacus.php,(16)serendipity_event_statistics/serendipity_plugin_statistics.php,(17)serendipity_event_templatechooser/serendipity_event_templatechooser.php,(18)serendipity_event_textile/serendipity_event_textile.php,(19)serendipity_event_textwiki/serendipity_event_textwiki.php,(20)serendipity_event_trackexits/serendipity_event_trackexits.php,(21)serendipity_event_weblogping/serendipity_event_weblogping.php,(22)serendipity_event_xhtmlcleanup/serendipity_event_xhtmlcleanup.php,(23)serendipity_plugin_comments/serendipity_plugin_comments.php,(24)serendipity_plugin_creativecommons/serendipity_plugin_creativecommons.php,(25)serendipity_plugin_entrylinks/serendipity_plugin_entrylinks.php,(26)serendipity_plugin_eventwrapper/serendipity_plugin_eventwrapper.php,(27)serendipity_plugin_history/serendipity_plugin_history.php,(28)serendipity_plugin_recententries/serendipity_plugin_recententries.php,(29)serendipity_plugin_remoterss/serendipity_plugin_remoterss.php,(30)serendipity_plugin_shoutbox/serendipity_plugin_shoutbox.php,(31)和(32)serendipity_plugin_templatedropdown/serendipity_plugin_templatedropdown.php内的serendipity[charset]参数(该参数中包含..)序列来读取或包含任意本地文件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
S9Y Serendipity 1.0.beta 2
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 1.0.beta 3
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.3
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.4
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.5
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.5 -pl1
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.6
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.6 -rc1
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.6 -pl3
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.6 -rc2
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.6 -pl2
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.6 -pl1
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.7 -rc1
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.7 beta1
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.7 beta3
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.7
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.7 -beta4
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.7 -beta2
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.7.1
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.8
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.8 -beta6
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.8 -beta5
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.8 -beta6 Snapshot
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.8.1
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.8.2
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 0.9.1
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
S9Y Serendipity 1.0.3
S9Y serendipity-1.0.4a.tar.gz
http://prdownloads.sourceforge.net/php-blog/serendipity-1.0.4a.tar.gz
参考网址
来源: VUPEN
名称: ADV-2006-4782
链接:http://www.frsirt.com/english/advisories/2006/4782
来源: XF
名称: serendipity-lang-file-include(30615)
链接:http://xforce.iss.net/xforce/xfdb/30615
来源: BID
名称: 21367
链接:http://www.securityfocus.com/bid/21367
来源: MISC
链接:http://www.s9y.org/forums/viewtopic.php?t=7922
来源: MILW0RM
名称: 2869
链接:http://www.milw0rm.com/exploits/2869
来源: MILW0RM
名称: 2869