CVE-2023-49103: OwnCloud – Phpinfo Configuration

CVE-2023-49103: OwnCloud - Phpinfo Configuration-渗透云记 - 专注于网络安全与技术分享
CVE-2023-49103: OwnCloud – Phpinfo Configuration
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-49103: OwnCloud – Phpinfo Configuration

漏洞描述

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享