发布时间 :2006-02-21 21:02:00
修订时间 :2008-09-05 17:00:22

[原文]Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password.

[CNNVD]Leif M. Wright Blog信息泄露漏洞(CNNVD-200602-324)

        Leif M. Wright's Blog 3.5在没有足够访问控制的web root中存储配置文件和其他txt文件,从而使得远程攻击者可以读取管理员密码。

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: NONE [对系统可用性无影响]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)


- OVAL (用于检测的技术细节)


- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  BID  16712
(UNKNOWN)  XF  webblog-txt-obtain-information(24752)

- 漏洞信息

Leif M. Wright Blog信息泄露漏洞
中危 设计错误
2006-02-21 00:00:00 2006-02-22 00:00:00
        Leif M. Wright's Blog 3.5在没有足够访问控制的web root中存储配置文件和其他txt文件,从而使得远程攻击者可以读取管理员密码。

- 公告与补丁


- 漏洞信息 (F44315)

EV0082.txt (PacketStormID:F44315)
2006-03-03 00:00:00
Aliaksandr Hartsuyeu
exploit,code execution,xss,info disclosure

Leif M. Wright's Blog version 3.5 is susceptible to information disclosure, authentication bypass, code execution, and cross site scripting flaws. Exploit details provided.

New eVuln Advisory:
Leif M. Wright's Blog Multiple Vulnerabilities

eVuln ID: EV0082
CVE: CVE-2006-0843 CVE-2006-0844 CVE-2006-0845 CVE-2006
Software: Leif M. Wright's Blog
Sowtware's Web Site:
Versions: 3.5
Critical Level: Dangerous
Type: Multiple Vulnerabilities
Class: Remote
Status: Unpatched. No reply from developer(s)
Exploit: Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (

1. Sensitive Information Disclosure and Authentication Bypass

All "txt" files isn't protected by htaccess(or any other ways) in default installiation. This can be used to retrieve administrator's password from config file.

2. Cookie Authentication Bypass

"blog.cgi" script dont make password comparisson when identifying administrator by cookie.

3. Shell Command Execution

Administrator has an ability to edit blog configuration including full path to sendmail program. This can be used to execute arbitrary shell commands.

System access is possible.

4. 'Referer' and 'User-Agent' Cross-Site Scripting

Environment variables HTTP_REFERER and HTTP_USER_AGENT are not properly sanitized. This can be used to post HTTP query with fake Referer or User-Agent values which may contain arbitrary html or script code. This code will be executed when administrator will open "Log" page.

Available at:

1. Sensitive Information Disclosure and Authentication Bypass

Url example:

2. Cookie Authentication Bypass

Cookie: blogAdmin=true

3. Shell Command Execution

Sendmail: /bin/ls

4. 'Referer' and 'User-Agent' Cross-Site Scripting

GET /cgi-bin/blog/blog.cgi HTTP/1.0
Host: [host]
Referer: [XSS]
User-Agent: [XSS]
Content-Type: application/x-www-form-urlencoded
Content-Length: 93

file=15-13.59.39.txt&year=2006&month=February&name=zz&comment=zzz&submit=Enter% 20my%20comment

No Patch available.

Discovered by: Aliaksandr Hartsuyeu (

Aliaksandr Hartsuyeu - Penetration Testing Services

- 漏洞信息

Leif M. Wright's Blog Config File Admin Password Remote Disclosure
Remote / Network Access

- 漏洞描述

Unknown or Incomplete

- 时间线

2006-02-15 Unknow
Unknow Unknow

- 解决方案

Unknown or Incomplete

- 相关参考

- 漏洞作者

Unknown or Incomplete