This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: A path disclosure flaw in Webzyme Couch CMS. ๐ฅ **Consequences**: Attackers can retrieve the **full server file path** via direct requests to specific PHP files.โฆ
๐ก๏ธ **Root Cause**: Improper error handling or path exposure in PHP scripts. ๐ **Flaw**: The files `includes/mysql2i/mysql2i.func.php` and `addons/phpmailer/phpmailer.php` expose internal paths when accessed directly.โฆ
๐ฅ **Affected**: Webzyme Couch CMS. ๐ฆ **Versions**: Version **2.0 and earlier**. ๐ข **Vendor**: Webzyme Softwares (US-based).
Q4What can hackers do? (Privileges/Data)
๐ต๏ธ **Hackers Can**: Discover the **absolute full path** of the web root. ๐ **Impact**: This info helps attackers map the server structure, potentially facilitating Local File Inclusion (LFI) or other path-based exploits.
Q5Is exploitation threshold high? (Auth/Config)
๐ **Threshold**: **LOW**. ๐ซ **Auth**: No authentication required. โ๏ธ **Config**: Exploitable via **direct HTTP requests** to specific endpoints. Anyone on the internet can trigger it.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ **Public Exp?**: **YES**. ๐งช **PoC**: Available via Nuclei templates (ProjectDiscovery).โฆ
๐ **Self-Check**: Scan for direct access to: 1. `/includes/mysql2i/mysql2i.func.php` 2. `/addons/phpmailer/phpmailer.php`. ๐ก **Tool**: Use Nuclei or custom scripts to check for path leakage in responses.
Q8Is it fixed officially? (Patch/Mitigation)
๐ ๏ธ **Fix**: Update to a version **newer than 2.0**. ๐ฅ **Patch**: Check official GitHub issues for updates. ๐ **Ref**: [CouchCMS Issue #46](https://github.com/CouchCMS/CouchCMS/issues/46).
Q9What if no patch? (Workaround)
๐ง **No Patch?**: Block direct access to the vulnerable PHP files via **Web Application Firewall (WAF)** or **Nginx/Apache config**. ๐ซ **Rule**: Deny requests to `mysql2i.func.php` and `phpmailer.php` if not needed.
Q10Is it urgent? (Priority Suggestion)
โก **Urgency**: **HIGH**. ๐ **Published**: March 2018. ๐ฏ **Priority**: Immediate patching recommended. Path disclosure is a critical stepping stone for deeper server compromise.