CVE-2006-3554
CVSS7.5
发布时间 :2006-07-12 20:05:00
修订时间 :2017-07-19 21:32:23
NMCO    

[原文]Directory traversal vulnerability in index.php in MKPortal 1.0.1 Final allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by using a gl_session cookie to inject PHP sequences into the error.log file, which is then included by index.php with malicious commands accessible by the ind parameter.


[CNNVD]MKPortal 'Index.PHP'目录遍历漏洞(CNNVD-200607-188)

        MKPortal 1.0.1 Final中的index.php存在目录遍历漏洞。远程攻击者可以借助语言cookie中的目录遍历序列,包含并执行任意本地文件。比如使用gl_session cookie将PHP序列注入error.log 文件, 然后由带有可由ind参数访问的恶意命令的 index.php所包含。

- CVSS (基础分值)

CVSS分值: 7.5 [严重(HIGH)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CPE (受影响的平台与产品)

产品及版本信息(CPE)暂不可用

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3554
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3554
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200607-188
(官方数据源) CNNVD

- 其它链接及资源

http://securityreason.com/securityalert/1234
(UNKNOWN)  SREASON  1234
http://securitytracker.com/id?1016403
(UNKNOWN)  SECTRACK  1016403
http://www.securityfocus.com/archive/1/archive/1/438614/100/100/threaded
(UNKNOWN)  BUGTRAQ  20060628 MKPortal 1.0.1 Final ($ind) File Include Vulnerability (perl)
http://www.securityfocus.com/bid/18707
(UNKNOWN)  BID  18707
http://www.vupen.com/english/advisories/2006/2598
(UNKNOWN)  VUPEN  ADV-2006-2598
http://www.worlddefacers.de/Public/WD-MKP.txt
(UNKNOWN)  MISC  http://www.worlddefacers.de/Public/WD-MKP.txt
https://exchange.xforce.ibmcloud.com/vulnerabilities/27451
(UNKNOWN)  XF  mkportal-index-file-include(27451)

- 漏洞信息

MKPortal 'Index.PHP'目录遍历漏洞
高危 sgn=/en 紧急程度 font-weight>