涉及程序: Xoops 2.0版及其之前的版本 描述: Xoops存在路径泄露缺陷 详细: Xoops是一个用面向对象的PHP写的开源、免费的Web程序,它用MySQL作为后台数据库,可以运行于大多数的Unix/Linux系统。 Xoops存在缺陷,允许攻击者测定应用程序的物理路径。利用该缺陷,攻击者能测定WEB root目录的全部路径,并获取某些敏感信息。远程攻击者通过提交精心构造,含有“$xoopsOption”参数的下列格式的临时HTTP请求,能触发该缺陷: http://
/index.php?xoopsOption=any_word 受影响的文件: admin.php edituser.php footer.php header.php image.php lostpass.php pmlite.php readpmsg.php register.php search.php user.php userinfo.php viewpmsg.php class/xoopsblock.php modules/contact/index.php modules/mydownloads/index.php modules/mydownloads/brokenfile.php modules/mydownloads/modfile.php modules/mydownloads/ratefile.php modules/mydownloads/singlefile.php modules/mydownloads/submit.php modules/mydownloads/topten.php modules/mydownloads/viewcat.php modules/mylinks/brokenlink.php modules/mylinks/index.php modules/mylinks/modlink.php modules/mylinks/ratelink.php modules/mylinks/singlelink.php modules/mylinks/submit.php modules/mylinks/topten.php modules/mylinks/viewcat.php modules/newbb/index.php modules/newbb/search.php modules/newbb/viewforum.php modules/newbb/viewtopic.php modules/news/archive.php modules/news/article.php modules/news/index.php modules/sections/index.php modules/system/admin.php modules/xoopsfaq/index.php modules/xoopsheadlines/index.php modules/xoopsmembers/index.php modules/xoopspartners/index.php modules/xoopspartners/join.php modules/xoopspoll/index.php modules/xoopspoll/pollresults.php 攻击方法: 示例代码:: http://
/index.php?xoopsOption=any_word 解决方案: 目前厂商未公布该缺陷补丁,请用户及时关注厂商站点: http://www.xoops.org/