漏洞标题
N/A
漏洞描述信息
"Monkey Boards 0.3.5 允许远程攻击者通过直接请求 (1) include/admin_auth.inc.php 和 (2) include/engine/class.compiler.php 获取敏感信息,这在一个错误消息中揭示了完整的路径。注意:只有当管理员更改了默认脚本路径时,此问题才会暴露。"
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Monkey Boards 0.3.5 allows remote attackers to obtain sensitive information via direct requests to (1) include/admin_auth.inc.php and (2) include/engine/class.compiler.php, which reveals the full path in an error message. NOTE: this issue is only an exposure if the administrator has changed the default script path.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Monkey Boards 路径泄露漏洞
漏洞描述信息
Monkey Boards远程攻击者通过直接请求(1)include/admin_auth.inc.php和(2)include/engine/class.compiler.php,导致系统在出错消息内泄露完整路径,从而获取敏感信息。
CVSS信息
N/A
漏洞类别
授权问题