QID 730071
Date Published: 2021-05-10
QID 730071: DCP-Portal System Information Path Disclosure Vulnerability
DCP-Portal is a content management system that enables various Web-based updates. It enables an admin to remotely manage the site, and allows members to submit content, such as news and reviews.
If a user submits a request appended with 'add_user.php' to a host, then a "Cannot add header information" error message is returned. The error message contains part of the path for the 'add_user.php' file.
QID Detection Logic:
This QID checks for the vulnerable version by sending GET request to add_user.php
This vulnerability can be exploited to reveal the absolute path to the Web root, which can be used in further attacks against the vulnerable system.
Solution
Upgrade to DCP-Portal Version 4.5.1. Download the latest version from www.dcp-portal.com.
Vendor References
CVEs related to QID 730071
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| DCP Portal |
|