CVE-2014-8706 |
|
发布时间 :2017-03-17 10:59:00 | ||
修订时间 :2017-03-17 10:59:00 | ||||
NM |
[原文]Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing “PHPSESSIS” to an array; (2) adding non-aplhanumeric chars to “PHPSESSID”; (3) changing the image parameter to array; or (4) changing the image parameter to a string, which reveals the installation path in an error message.
[CNNVD]CNNVD数据暂缺。
[机译]Google 翻译(企业版):
–
CVSS (基础分值)
CVSS暂不可用 |
–
CPE (受影响的平台与产品)
产品及版本信息(CPE)暂不可用 |
–
OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
–
官方数据库链接
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8706 (官方数据源) MITRE |
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8706 (官方数据源) NVD |
–
其它链接及资源
http://rossmarks.uk/portfolio.php (UNKNOWN) MISC http://rossmarks.uk/portfolio.php |
http://rossmarks.uk/whitepapers/pluck_cms_4.7.txt (UNKNOWN) MISC http://rossmarks.uk/whitepapers/pluck_cms_4.7.txt |