Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-49103 PoC — ownCloud 安全漏洞

Source
Associated Vulnerability
Title:ownCloud 安全漏洞 (CVE-2023-49103)
Description:ownCloud是美国ownCloud公司的一套个人云存储解决方案。 ownCloud graphapi 0.2.1 之前、0.3.1 之前版本存在安全漏洞,该漏洞源于graphapi 应用程序依赖于提供 URL 的第三方 GetPhpInfo.php 库,当访问此 URL 时,它会显示 PHP 环境 (phpinfo) 的配置详细信息,这些信息包括网络服务器的所有环境变量,在容器化部署中,这些环境变量可能包括敏感数据,例如 ownCloud 管理员密码、邮件服务器凭据和许可证密钥,攻击者利用该漏洞可以从
Description
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system.
File Snapshot

id: CVE-2023-49103 info: name: OwnCloud - Phpinfo Configuration author: ritikchaddha severity ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.