PT-2019-7049 · Vembu · Vembu Storegrid

Gionathan Reale

+1

·

Publicado

2019-02-23

·

Atualizado

2019-03-18

·

CVE-2014-10079

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vembu StoreGrid version 4.4.x
Description The issue concerns the server web interface of Vembu StoreGrid, where the front page leaks the private IP address. This leak occurs due to incorrect processing of an index.php trailing slash, which discloses the private IP address in the ipaddress hidden form value of the HTML source code.
Recommendations For Vembu StoreGrid version 4.4.x, consider modifying the index.php page to correctly process trailing slashes and remove the disclosure of the private IP address in the ipaddress hidden form value. As a temporary workaround, restrict access to the server web interface to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-10079

Produtos afetados

Vembu Storegrid