Brief description:
Saming Network Technology Co., Ltd. is an open-source qibo CMS. The Admin_SiteMap.asp file does not filter the background address, leading to the vulnerability.
Detailed description:
The website is open-source by qibo CMS, because Admin_SiteMap.asp is not set to filter the background, leading to leakage of the background and editor in the website map.
Proof of vulnerability:
Solution:
Modify the Function Folderpermission (pathName) parameter of Admin_SiteMap.asp in the background directory)
PathExclusion = Array ("\ temp", "\ sanming", "\ _ vti_cnf", "_ vti_pvt", "_ vti_log", "cgi-bin ", "\ admin", "\ edu ")
Folderpermission = True
For each PathExcluded in PathExclusion
If instr (ucase (pathName), ucase (PathExcluded)> 0 then
Folderpermission = False
Exit
End if
Next
End Function
Enter the background directory.
Lu renjia @ wooyun