漏洞文件
templates/default/savepost.tpl.php

漏洞信息
Notice: Undefined index: boardid in /var/www/html/dvbbs1.0/templates/default/savepost.tpl.php on line 14
Notice: Undefined variable: board_settings in /var/www/html/dvbbs1.0/templates/default/savepost.tpl.php
on line 15Notice: Use of undefined constant INC_PATH - assumed 'INC_PATH' in /var/www/html/dvbbs1.0/t
emplates/default/savepost.tpl.php on line 72
Warning: main(INC_PATHBoardCache.class.php): failed to open stream: No such file or directory in /var/ww
w/html/dvbbs1.0/templates/default/savepost.tpl.php on line 72 Fatal error: main(): Failed opening required
'INC_PATHBoardCache.class.php' (include_path='.:/var/www/html/dvbbs') in
/var/www/html/dvbbs1.0/templates/default/savepost.tpl.php on line 72
喜欢0day的。。。。希望去查看漏洞文件。。
是否有利用价值自己阅读下 漏洞文件 就知道了。。。。
官方漏洞地址http://p.dvbbs.net/templates/default/savepost.tpl.php
在说个几个存在 隐患的漏洞文件
/admin/inc/board.form.php
/admin/inc/board_setting.form.php
/admin/inc/forum_ads.form.php
/admin/templates/default/audit_settings.tpl.php
/admin/templates/default/board.tpl.php
/admin/templates/default/forum_ads.tpl.php
/admin/templates/default/link.tpl.php
/admin/templates/default/user.tpl.php
/space/edit_plus/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php
(来源:http://www.hackxiu.cn/)