Grayscale BandSite CMS における重要な情報を取得される脆弱性
タイトル Grayscale BandSite CMS における重要な情報を取得される脆弱性
概要

Grayscale BandSite CMS は、エラーメッセージにパスを表示する不備があるため、重要な情報を取得される脆弱性が存在します。

想定される影響 第三者により、以下への直接リクエストを介して、重要な情報を取得される可能性があります。 (1) includes/content ディレクトリ内の特定のファイル (2) includes/shows_preview.php (3) adminpanel/configform.php (4) adminpanel/includes/ 内の mailinglist/disphtmltbl.php (5) adminpanel/includes/ 内の mailinglist/dispxls.php (6) adminpanel/includes/ 内の mailinglist/sendshows.php (7) adminpanel/includes/ 内の previews/preview_bio.php (8) adminpanel/includes/ 内の previews/preview_genmerch.php (9) adminpanel/includes/ 内の previews/preview_fliers.php (10) adminpanel/includes/ 内の previews/preview_gbook.php (11) adminpanel/includes/ 内の previews/preview_interviews.php (12) adminpanel/includes/ 内の previews/preview_links.php (13) adminpanel/includes/ 内の previews/preview_lyrics.php (14) adminpanel/includes/ 内の previews/preview_membio.php (15) adminpanel/includes/ 内の previews/preview_merchphotos.php (16) adminpanel/includes/ 内の previews/preview_mp3s.php (17) adminpanel/includes/ 内の previews/preview_news.php (18) adminpanel/includes/ 内の previews/preview_photos.php (19) adminpanel/includes/ 内の previews/preview_releases.php (20) adminpanel/includes/ 内の previews/preview_relmerch.php (21) adminpanel/includes/ 内の previews/preview_relphotos.php (22) adminpanel/includes/ 内の previews/preview_reviews.php (23) adminpanel/includes/ 内の previews/preview_shows.php (24) adminpanel/includes/ 内の previews/preview_wearmerch.php (25) adminpanel/includes/ 内の change_forms/change_bio.php (26) adminpanel/includes/ 内の change_forms/change_fliers.php (27) adminpanel/includes/ 内の change_forms/change_gbook.php (28) adminpanel/includes/ 内の change_forms/change_gen_merch.php (29) adminpanel/includes/ 内の change_forms/change_interview.php (30) adminpanel/includes/ 内の change_forms/change_links.php (31) adminpanel/includes/ 内の change_forms/change_lyrics.php (32) adminpanel/includes/ 内の change_forms/change_members.php (33) adminpanel/includes/ 内の change_forms/change_merch.php (34) adminpanel/includes/ 内の change_forms/change_merch_pic.php (35) adminpanel/includes/ 内の change_forms/change_mp3s.php (36) adminpanel/includes/ 内の change_forms/change_news.php (37) adminpanel/includes/ 内の change_forms/change_photos.php (38) adminpanel/includes/ 内の change_forms/change_rel_merch.php (39) adminpanel/includes/ 内の change_forms/change_rel_pic.php (40) adminpanel/includes/ 内の change_forms/change_releases.php (41) adminpanel/includes/ 内の change_forms/change_reviews.php (42) adminpanel/includes/ 内の change_forms/change_shows.php (43) adminpanel/includes/ 内の change_forms/change_wear_merch.php
対策

ベンダ情報および参考情報を参照して適切な対策を実施してください。

公表日 2006年9月25日0:00
登録日 2012年6月26日15:37
最終更新日 2012年6月26日15:37
CVSS2.0 : 警告
スコア 5
ベクター AV:N/AC:L/Au:N/C:P/I:N/A:N
影響を受けるシステム
grayscale
bandsite cms 
CVE (情報セキュリティ 共通脆弱性識別子)
ベンダー情報
変更履歴
No 変更内容 変更日
0 [2012年06月26日]
  掲載
2018年2月17日10:37

NVD脆弱性情報
CVE-2006-4986
概要

Grayscale BandSite CMS allows remote attackers to obtain sensitive information via a direct request for (1) certain files in the includes/content directory, (2) includes/shows_preview.php, and (3) adminpanel/configform.php; and files in adminpanel/includes/ including (4) mailinglist/disphtmltbl.php, (5) mailinglist/dispxls.php, (6) mailinglist/sendshows.php, (7) previews/preview_bio.php, (8) previews/preview_genmerch.php, (9) previews/preview_fliers.php, (10) previews/preview_gbook.php, (11) previews/preview_interviews.php, (12) previews/preview_links.php, (13) previews/preview_lyrics.php, (14) previews/preview_membio.php, (15) previews/preview_merchphotos.php, (16) previews/preview_mp3s.php, (17) previews/preview_news.php, (18) previews/preview_photos.php, (19) previews/preview_releases.php, (20) previews/preview_relmerch.php, (21) previews/preview_relphotos.php, (22) previews/preview_reviews.php, (23) previews/preview_shows.php, (24) previews/preview_wearmerch.php, (25) change_forms/change_bio.php, (26) change_forms/change_fliers.php, (27) change_forms/change_gbook.php, (28) change_forms/change_gen_merch.php, (29) change_forms/change_interview.php, (30) change_forms/change_links.php, (31) change_forms/change_lyrics.php, (32) change_forms/change_members.php, (33) change_forms/change_merch.php, (34) change_forms/change_merch_pic.php, (35) change_forms/change_mp3s.php, (36) change_forms/change_news.php, (37) change_forms/change_photos.php, (38) change_forms/change_rel_merch.php, (39) change_forms/change_rel_pic.php, (40) change_forms/change_releases.php, (41) change_forms/change_reviews.php, (42) change_forms/change_shows.php, and (43) change_forms/change_wear_merch.php, which reveals the path in various error messages.

公表日 2006年9月26日11:07
登録日 2021年1月29日15:46
最終更新日 2018年10月18日6:40
影響を受けるソフトウェアの構成
構成1 以上 以下 より上 未満
cpe:2.3:a:grayscale:bandsite_cms:1.1:*:*:*:*:*:*:*
関連情報、対策とツール
共通脆弱性一覧