发新话题
打印

[转载]aeNovo数据库目录泄露漏洞

[转载]aeNovo数据库目录泄露漏洞

信息来源:ACE

Summary
aeNovo is "a web content management system". Due to improper file permission settings in aeNovo, a remote user can download the product's mdb file (Database file) and gain access to sensitive information.

Credit:
The information has been provided by farhad koosha.

Details
Exploit:
By accessing the directory /dbase/ and the file aeNovo1.mdb, a remote attacker can access the aeNovo's database, and pull from it sensitive information such as the administrative username and password.
曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题