EJ3 BlackBook Information Disclosure Vulnerability
BID:8189
Info
EJ3 BlackBook Information Disclosure Vulnerability
| Bugtraq ID: | 8189 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2003 12:00AM |
| Updated: | Jul 14 2003 12:00AM |
| Credit: | Reported by "morning_wood" <[email protected]>. |
| Vulnerable: |
EJ3 BlackBook 1.0 |
| Not Vulnerable: | |
Discussion
EJ3 BlackBook Information Disclosure Vulnerability
It has been reported that the BlackBook installation routine does not properly set filesystem permissions on the /blackbook/data/data.dat file. This file contains posts made to the guestbook, as well as associated usernames and IP addresses for each post. Users may be able to read this file and retrieve sensitive information associated with a given user.
It has been reported that the BlackBook installation routine does not properly set filesystem permissions on the /blackbook/data/data.dat file. This file contains posts made to the guestbook, as well as associated usernames and IP addresses for each post. Users may be able to read this file and retrieve sensitive information associated with a given user.
Exploit / POC
EJ3 BlackBook Information Disclosure Vulnerability
This vulnerability can be exploited with a Web browser.
This vulnerability can be exploited with a Web browser.
Solution / Fix
EJ3 BlackBook Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EJ3 BlackBook Information Disclosure Vulnerability
References:
References:
- BlackBook Homepage (EJ3)
- BlackBook - Multiple Vunerabilities ("morning_wood"
)