Bluview Blue Magic Board (BMB)(也称为BMForum)5.5,远程攻击者可以通过直接请求(1) footer.php, (2) header.php, (3) db_mysql_error.php, (4) langlist.php, (5) sendmail.php或(6) style.php,在各种错误消息中揭示路径,从而获取敏感信息。
来源: BUGTRAQ
名称: 20060914 Fullpath disclosure in Blue Magic Board 5.5
链接:http://www.securityfocus.com/archive/1/archive/1/446037/100/0/threaded
来源: XF
名称: bluemagicboard-footer-path-disclosure(28949)
链接:http://xforce.iss.net/xforce/xfdb/28949
来源: SREASON
名称: 1586
链接:http://securityreason.com/securityalert/1586
暂无