CNCVE编号:CNCVE-20020042 CVE编号: 安全级别:低 漏洞中文描述: DCP-Portal是种内容管理系统,提供多种基于WEB方式的操作,比如更新站点、成员管理等等。Dcp-Portal存在一个漏洞,远程用户可以获取WWW根目录的绝对路径。当用户提交如下URL请求时http://www.dcp-portal_host.com.tr/add_user.php系统返回如下信息"Warning: Cannot add header information - headers already sent by (output started at /home/usr/www.dcp-portal_host/htdocs/add_user.php:11) in /home/usr/www.dcp-portal_host/htdocs/add_user.php on line 16"攻击者可能利用这些信息进行其它攻击。 漏洞英文描述: DCP-Portal is a content management system which enables various web based updates. It enables an admin to remotely manage the entire site, and allows for members to submit news/content and reviews etc. An issue has been reported in DCP-Portal, which could enable a remote user to reveal the absolute path to the web root. Reportedly, invalid requests made to a host, will return an error message including the path to the web root. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0163.html http://www.dcp-portal.com/ 系统类型:其他 漏洞类型:设计错误