PT-2009-6586 · Deluxebb · Deluxebb
Cp77Fk4R
·
Publicado
2009-12-30
·
Atualizado
2017-08-17
·
CVE-2009-4465
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DeluxeBB version 1.3
Description
The issue allows remote attackers to obtain sensitive information, including user and configuration data, log files, and gain administrative access. This is possible due to the storage of sensitive information under the web root with insufficient access control. Attackers can access scripts in various directories, such as
templates/, images/, logs/, wysiwyg/, docs/, classes/, lang/, and settings/, via a direct request. Specifically, attackers can target directories like templates/deluxe/admincp/, templates/corporate/admincp/, and templates/blue/admincp/, as well as files like logs/cp.php.Recommendations
For DeluxeBB version 1.3, consider restricting direct access to sensitive directories and files, such as
templates/, images/, logs/, wysiwyg/, docs/, classes/, lang/, and settings/, to prevent unauthorized access. As a temporary workaround, restrict access to the logs/ directory and files like logs/cp.php to minimize the risk of exploitation. Additionally, limit access to administrative scripts in templates/deluxe/admincp/, templates/corporate/admincp/, and templates/blue/admincp/ until a proper fix is applied.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Deluxebb