HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, which calls the phpinfo function.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://osvdb.org/55962 | vdb entry |
http://secunia.com/advisories/35895 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51830 | vdb entry |
http://packetstormsecurity.org/0907-exploits/hubscript-xssphpinfo.txt | exploit |