EJ3 BlackBook phpinfo.php Information Disclosure Weakness
BID:8190
Info
EJ3 BlackBook phpinfo.php Information Disclosure Weakness
| Bugtraq ID: | 8190 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2003 12:00AM |
| Updated: | Jul 14 2003 12:00AM |
| Credit: | Reported by "morning_wood" <[email protected]>. |
| Vulnerable: |
EJ3 BlackBook 1.0 |
| Not Vulnerable: | |
Discussion
EJ3 BlackBook phpinfo.php Information Disclosure Weakness
It has been reported that BlackBook enables a script by default that may reveal sensitive information. The phpinfo.php script is packaged with BlackBook, and installed by default in the administrator subdirectory. A remote user may use this script to gain information about the server, including path and environment information.
It has been reported that BlackBook enables a script by default that may reveal sensitive information. The phpinfo.php script is packaged with BlackBook, and installed by default in the administrator subdirectory. A remote user may use this script to gain information about the server, including path and environment information.
Exploit / POC
EJ3 BlackBook phpinfo.php Information Disclosure Weakness
This vulnerability can be exploited with a Web browser.
This vulnerability can be exploited with a Web browser.
Solution / Fix
EJ3 BlackBook phpinfo.php Information Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EJ3 BlackBook phpinfo.php Information Disclosure Weakness
References:
References:
- BlackBook Homepage (EJ3)
- BlackBook - Multiple Vunerabilities ("morning_wood"
)