CVE-2009-3600 Information

Description

HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php which calls the phpinfo function.

Reference

http://osvdb.org/55962 http://packetstormsecurity.org/0907-exploits/hubscript-xssphpinfo.txt http://secunia.com/advisories/35895 https://exchange.xforce.ibmcloud.com/vulnerabilities/51830

Share on: