Super Guestbook Sensitive Information Disclosure Weakness
BID:7319
Info
Super Guestbook Sensitive Information Disclosure Weakness
| Bugtraq ID: | 7319 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2003 12:00AM |
| Updated: | Apr 10 2003 12:00AM |
| Credit: | Discovery of this weakness has been credited to Over G <[email protected]>. |
| Vulnerable: |
Super Guestbook Super Guestbook 1.0 |
| Not Vulnerable: | |
Discussion
Super Guestbook Sensitive Information Disclosure Weakness
Super Guestbook has been reported prone to a sensitive information disclosure weakness.
An attacker may disclose sensitive information regarding the Super Guestbook install by sending a HTTP request for a Guest Book configuration file. Details including administration credentials are displayed in the attackers browser.
Super Guestbook has been reported prone to a sensitive information disclosure weakness.
An attacker may disclose sensitive information regarding the Super Guestbook install by sending a HTTP request for a Guest Book configuration file. Details including administration credentials are displayed in the attackers browser.
Exploit / POC
Super Guestbook Sensitive Information Disclosure Weakness
The following proof of concept has been supplied:
http://www.example.com/cgi-bin/SGB_DIR/superguestconfig
The following proof of concept has been supplied:
http://www.example.com/cgi-bin/SGB_DIR/superguestconfig
Solution / Fix
Super Guestbook Sensitive Information Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.