漏洞标题
N/A
漏洞描述信息
Craig Knudsen WebCalendar 1.1.0-CVS 允许远程攻击者通过直接请求(1)包括/index.php,(2)测试/添加持久测试.php,(3)测试/所有测试.php,(4)组.php,(5)非用户.php,(6)包括/设置.php,(7)包括/初始化.php,(8)包括/设置.php. orig,(9)包括/js/admin.php,(10)包括/js/编辑字段.php,(11)包括/js/编辑层.php,(12)包括/js/导出导入.php,(13)包括/js/弹出.php,(14)包括/js/预置.php,或(15)包括/菜单/index.php,从而暴露在各种错误消息中的路径。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9) includes/js/admin.php, (10) includes/js/edit_entry.php, (11) includes/js/edit_layer.php, (12) includes/js/export_import.php, (13) includes/js/popups.php, (14) includes/js/pref.php, or (15) includes/menu/index.php, which reveal the path in various error messages.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Craig Knudsen WebCalendar 直接请求敏感信息泄露漏洞
漏洞描述信息
Craig Knudsen WebCalendar 1.1.0-CVS可以让远程攻击者通过以下途径获取敏感信息:一条直接请求发往(1) includes/index.php,(2) tests/add_duration_test.php,(3) tests/all_tests.php,(4) groups.php,(5) nonusers.php,(6) includes/settings.php,(7) includes/init.php,(8) includes/settings.php.orig,(
CVSS信息
N/A
漏洞类别
授权问题