| タイトル | Grayscale BandSite CMS における重要な情報を取得される脆弱性 |
|---|---|
| 概要 | Grayscale BandSite CMS は、エラーメッセージにパスを表示する不備があるため、重要な情報を取得される脆弱性が存在します。 |
| 想定される影響 | 第三者により、以下への直接リクエストを介して、重要な情報を取得される可能性があります。 (1) includes/content ディレクトリ内の特定のファイル (2) includes/shows_preview.php (3) adminpanel/configform.php (4) adminpanel/includes/ 内の mailinglist/disphtmltbl.php (5) adminpanel/includes/ 内の mailinglist/dispxls.php (6) adminpanel/includes/ 内の mailinglist/sendshows.php (7) adminpanel/includes/ 内の previews/preview_bio.php (8) adminpanel/includes/ 内の previews/preview_genmerch.php (9) adminpanel/includes/ 内の previews/preview_fliers.php (10) adminpanel/includes/ 内の previews/preview_gbook.php (11) adminpanel/includes/ 内の previews/preview_interviews.php (12) adminpanel/includes/ 内の previews/preview_links.php (13) adminpanel/includes/ 内の previews/preview_lyrics.php (14) adminpanel/includes/ 内の previews/preview_membio.php (15) adminpanel/includes/ 内の previews/preview_merchphotos.php (16) adminpanel/includes/ 内の previews/preview_mp3s.php (17) adminpanel/includes/ 内の previews/preview_news.php (18) adminpanel/includes/ 内の previews/preview_photos.php (19) adminpanel/includes/ 内の previews/preview_releases.php (20) adminpanel/includes/ 内の previews/preview_relmerch.php (21) adminpanel/includes/ 内の previews/preview_relphotos.php (22) adminpanel/includes/ 内の previews/preview_reviews.php (23) adminpanel/includes/ 内の previews/preview_shows.php (24) adminpanel/includes/ 内の previews/preview_wearmerch.php (25) adminpanel/includes/ 内の change_forms/change_bio.php (26) adminpanel/includes/ 内の change_forms/change_fliers.php (27) adminpanel/includes/ 内の change_forms/change_gbook.php (28) adminpanel/includes/ 内の change_forms/change_gen_merch.php (29) adminpanel/includes/ 内の change_forms/change_interview.php (30) adminpanel/includes/ 内の change_forms/change_links.php (31) adminpanel/includes/ 内の change_forms/change_lyrics.php (32) adminpanel/includes/ 内の change_forms/change_members.php (33) adminpanel/includes/ 内の change_forms/change_merch.php (34) adminpanel/includes/ 内の change_forms/change_merch_pic.php (35) adminpanel/includes/ 内の change_forms/change_mp3s.php (36) adminpanel/includes/ 内の change_forms/change_news.php (37) adminpanel/includes/ 内の change_forms/change_photos.php (38) adminpanel/includes/ 内の change_forms/change_rel_merch.php (39) adminpanel/includes/ 内の change_forms/change_rel_pic.php (40) adminpanel/includes/ 内の change_forms/change_releases.php (41) adminpanel/includes/ 内の change_forms/change_reviews.php (42) adminpanel/includes/ 内の change_forms/change_shows.php (43) adminpanel/includes/ 内の change_forms/change_wear_merch.php |
| 対策 | ベンダ情報および参考情報を参照して適切な対策を実施してください。 |
| 公表日 | 2006年9月25日0:00 |
| 登録日 | 2012年6月26日15:37 |
| 最終更新日 | 2012年6月26日15:37 |
| CVSS2.0 : 警告 | |
| スコア | 5 |
|---|---|
| ベクター | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| grayscale |
| bandsite cms |
| No | 変更内容 | 変更日 |
|---|---|---|
| 0 | [2012年06月26日] 掲載 |
2018年2月17日10:37 |
| 概要 | Grayscale BandSite CMS allows remote attackers to obtain sensitive information via a direct request for (1) certain files in the includes/content directory, (2) includes/shows_preview.php, and (3) adminpanel/configform.php; and files in adminpanel/includes/ including (4) mailinglist/disphtmltbl.php, (5) mailinglist/dispxls.php, (6) mailinglist/sendshows.php, (7) previews/preview_bio.php, (8) previews/preview_genmerch.php, (9) previews/preview_fliers.php, (10) previews/preview_gbook.php, (11) previews/preview_interviews.php, (12) previews/preview_links.php, (13) previews/preview_lyrics.php, (14) previews/preview_membio.php, (15) previews/preview_merchphotos.php, (16) previews/preview_mp3s.php, (17) previews/preview_news.php, (18) previews/preview_photos.php, (19) previews/preview_releases.php, (20) previews/preview_relmerch.php, (21) previews/preview_relphotos.php, (22) previews/preview_reviews.php, (23) previews/preview_shows.php, (24) previews/preview_wearmerch.php, (25) change_forms/change_bio.php, (26) change_forms/change_fliers.php, (27) change_forms/change_gbook.php, (28) change_forms/change_gen_merch.php, (29) change_forms/change_interview.php, (30) change_forms/change_links.php, (31) change_forms/change_lyrics.php, (32) change_forms/change_members.php, (33) change_forms/change_merch.php, (34) change_forms/change_merch_pic.php, (35) change_forms/change_mp3s.php, (36) change_forms/change_news.php, (37) change_forms/change_photos.php, (38) change_forms/change_rel_merch.php, (39) change_forms/change_rel_pic.php, (40) change_forms/change_releases.php, (41) change_forms/change_reviews.php, (42) change_forms/change_shows.php, and (43) change_forms/change_wear_merch.php, which reveals the path in various error messages. |
|---|---|
| 公表日 | 2006年9月26日11:07 |
| 登録日 | 2021年1月29日15:46 |
| 最終更新日 | 2018年10月18日6:40 |
| 構成1 | 以上 | 以下 | より上 | 未満 | |
| cpe:2.3:a:grayscale:bandsite_cms:1.1:*:*:*:*:*:*:* | |||||