EZ Publish site.ini Information Disclosure Vulnerability
BID:7347
Info
EZ Publish site.ini Information Disclosure Vulnerability
| Bugtraq ID: | 7347 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2003 12:00AM |
| Updated: | Apr 15 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Gregory Le Bras <[email protected]>. |
| Vulnerable: |
eZ Systems eZ publish 3.0 eZ Systems eZ publish 2.2.7 |
| Not Vulnerable: | |
Discussion
EZ Publish site.ini Information Disclosure Vulnerability
eZ Publish has been reported prone to sensitive information disclosure vulnerability.
An attacker may make a request for and download the underlying site.ini configuration file. The file contains eZ Publish administration credentials stored in plaintext format. Any HTTP requests for this file will reveal the contents of this file to remote attackers.
eZ Publish has been reported prone to sensitive information disclosure vulnerability.
An attacker may make a request for and download the underlying site.ini configuration file. The file contains eZ Publish administration credentials stored in plaintext format. Any HTTP requests for this file will reveal the contents of this file to remote attackers.
Exploit / POC
EZ Publish site.ini Information Disclosure Vulnerability
The following proof of concept was provided:
http://[target]/settings/site.ini
The following proof of concept was provided:
http://[target]/settings/site.ini
Solution / Fix
EZ Publish site.ini Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EZ Publish site.ini Information Disclosure Vulnerability
References:
References:
- eZ Publish Homepage (eZ Publish)
- Security Corporation Security Advisory [SCSA-016] (
)