Zanfi CMS Lite 1.1 consente agli aggressori remoti di ottenere il percorso completo del server web tramite richieste dirette senza argomenti necessari per (1) adm_pages.php, (2) corr_pages.php, (3) del_block.php, (4) del_page.php , (5) footer.php, (6) home.php, e altri. |
http://www.securityfocus.com/archive/1/378053 http://www.zanfi.nl/index1.php?flag=cmslite http://www.osvdb.org/10677 http://www.osvdb.org/10678 http://www.osvdb.org/10679 http://www.osvdb.org/10680 http://www.osvdb.org/10681 http://www.osvdb.org/10682 http://securitytracker.com/id?1011612 http://secunia.com/advisories/12792 https://exchange.xforce.ibmcloud.com/vulnerabilities/17687 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2196 |
Vulnerabilità: CVE-2004-2196
