製品・ソフトウェアに関する情報
Grayscale BandSite CMS における重要な情報を取得される脆弱性
Title Grayscale BandSite CMS における重要な情報を取得される脆弱性
Summary

Grayscale BandSite CMS は、エラーメッセージにパスを表示する不備があるため、重要な情報を取得される脆弱性が存在します。

Possible impacts 第三者により、以下への直接リクエストを介して、重要な情報を取得される可能性があります。 (1) includes/content ディレクトリ内の特定のファイル (2) includes/shows_preview.php (3) adminpanel/configform.php (4) adminpanel/includes/ 内の mailinglist/disphtmltbl.php (5) adminpanel/includes/ 内の mailinglist/dispxls.php (6) adminpanel/includes/ 内の mailinglist/sendshows.php (7) adminpanel/includes/ 内の previews/preview_bio.php (8) adminpanel/includes/ 内の previews/preview_genmerch.php (9) adminpanel/includes/ 内の previews/preview_fliers.php (10) adminpanel/includes/ 内の previews/preview_gbook.php (11) adminpanel/includes/ 内の previews/preview_interviews.php (12) adminpanel/includes/ 内の previews/preview_links.php (13) adminpanel/includes/ 内の previews/preview_lyrics.php (14) adminpanel/includes/ 内の previews/preview_membio.php (15) adminpanel/includes/ 内の previews/preview_merchphotos.php (16) adminpanel/includes/ 内の previews/preview_mp3s.php (17) adminpanel/includes/ 内の previews/preview_news.php (18) adminpanel/includes/ 内の previews/preview_photos.php (19) adminpanel/includes/ 内の previews/preview_releases.php (20) adminpanel/includes/ 内の previews/preview_relmerch.php (21) adminpanel/includes/ 内の previews/preview_relphotos.php (22) adminpanel/includes/ 内の previews/preview_reviews.php (23) adminpanel/includes/ 内の previews/preview_shows.php (24) adminpanel/includes/ 内の previews/preview_wearmerch.php (25) adminpanel/includes/ 内の change_forms/change_bio.php (26) adminpanel/includes/ 内の change_forms/change_fliers.php (27) adminpanel/includes/ 内の change_forms/change_gbook.php (28) adminpanel/includes/ 内の change_forms/change_gen_merch.php (29) adminpanel/includes/ 内の change_forms/change_interview.php (30) adminpanel/includes/ 内の change_forms/change_links.php (31) adminpanel/includes/ 内の change_forms/change_lyrics.php (32) adminpanel/includes/ 内の change_forms/change_members.php (33) adminpanel/includes/ 内の change_forms/change_merch.php (34) adminpanel/includes/ 内の change_forms/change_merch_pic.php (35) adminpanel/includes/ 内の change_forms/change_mp3s.php (36) adminpanel/includes/ 内の change_forms/change_news.php (37) adminpanel/includes/ 内の change_forms/change_photos.php (38) adminpanel/includes/ 内の change_forms/change_rel_merch.php (39) adminpanel/includes/ 内の change_forms/change_rel_pic.php (40) adminpanel/includes/ 内の change_forms/change_releases.php (41) adminpanel/includes/ 内の change_forms/change_reviews.php (42) adminpanel/includes/ 内の change_forms/change_shows.php (43) adminpanel/includes/ 内の change_forms/change_wear_merch.php
Solution

ベンダ情報および参考情報を参照して適切な対策を実施してください。

Publication Date Sept. 25, 2006, midnight
Registration Date June 26, 2012, 3:37 p.m.
Last Update June 26, 2012, 3:37 p.m.
CVSS2.0 : 警告
Score 5
Vector AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected System
grayscale
bandsite cms 
CVE (情報セキュリティ 共通脆弱性識別子)
ベンダー情報
Change Log
No Changed Details Date of change
0 [2012年06月26日]
  掲載
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2006-4986
Summary

Grayscale BandSite CMS allows remote attackers to obtain sensitive information via a direct request for (1) certain files in the includes/content directory, (2) includes/shows_preview.php, and (3) adminpanel/configform.php; and files in adminpanel/includes/ including (4) mailinglist/disphtmltbl.php, (5) mailinglist/dispxls.php, (6) mailinglist/sendshows.php, (7) previews/preview_bio.php, (8) previews/preview_genmerch.php, (9) previews/preview_fliers.php, (10) previews/preview_gbook.php, (11) previews/preview_interviews.php, (12) previews/preview_links.php, (13) previews/preview_lyrics.php, (14) previews/preview_membio.php, (15) previews/preview_merchphotos.php, (16) previews/preview_mp3s.php, (17) previews/preview_news.php, (18) previews/preview_photos.php, (19) previews/preview_releases.php, (20) previews/preview_relmerch.php, (21) previews/preview_relphotos.php, (22) previews/preview_reviews.php, (23) previews/preview_shows.php, (24) previews/preview_wearmerch.php, (25) change_forms/change_bio.php, (26) change_forms/change_fliers.php, (27) change_forms/change_gbook.php, (28) change_forms/change_gen_merch.php, (29) change_forms/change_interview.php, (30) change_forms/change_links.php, (31) change_forms/change_lyrics.php, (32) change_forms/change_members.php, (33) change_forms/change_merch.php, (34) change_forms/change_merch_pic.php, (35) change_forms/change_mp3s.php, (36) change_forms/change_news.php, (37) change_forms/change_photos.php, (38) change_forms/change_rel_merch.php, (39) change_forms/change_rel_pic.php, (40) change_forms/change_releases.php, (41) change_forms/change_reviews.php, (42) change_forms/change_shows.php, and (43) change_forms/change_wear_merch.php, which reveals the path in various error messages.

Publication Date Sept. 26, 2006, 11:07 a.m.
Registration Date Jan. 29, 2021, 3:46 p.m.
Last Update Oct. 18, 2018, 6:40 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:grayscale:bandsite_cms:1.1:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List