当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-083407

漏洞标题:慕课科技某分站.svn信息泄漏

相关厂商:慕课科技

漏洞作者: Summer

提交时间:2014-11-17 14:57

修复时间:2014-11-22 14:58

公开时间:2014-11-22 14:58

漏洞类型:系统/服务运维配置不当

危害等级:中

自评Rank:10

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-11-17: 细节已通知厂商并且等待厂商处理中
2014-11-22: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

详细说明:

http://daxue.imooc.com/.svn/entries

10
dir
603
http://svn.imooc.com/svn/edu/trunk/webroot
http://svn.imooc.com/svn/edu
2014-07-08T07:15:37.056400Z
603
yangmy
a4e448a1-2505-4e08-8786-d8e16af91e2c
head.jpg
file
2014-05-08T10:05:29.000000Z
ceec3b41418b08a80ce5e4912eacfad0
2014-05-08T10:10:00.974995Z
18
yuanxch
has-props
35325
crossdomain.xml
file
2014-07-08T07:07:41.000000Z
09f73155628b45e7773da82f646c5ec1
2014-07-08T07:08:20.542206Z
597
yuanxch
321
cms
dir
face.php
file
2014-05-08T10:05:29.000000Z
7c16e8a987d166390d82679c58c4a731
2014-05-08T10:10:00.974995Z
18
yuanxch
1543
upload
dir
cotest.php
file
2014-05-08T10:05:29.000000Z
087852dcebbbd5250a2ccc7fdbf3541c
2014-05-08T10:10:00.974995Z
18
yuanxch
23
static
dir
wap
dir
space
dir
xhprof_lib
dir
editor_demo.html
file
2014-05-08T10:05:29.000000Z
10dc3ad2e3f07a91339e06717673362c
2014-05-08T10:10:00.974995Z
18
yuanxch
6124
cms_code_editor.js
file
2014-05-08T10:05:29.000000Z
b39e08921e6ad1669edf243bb5d8a6c5
2014-05-08T10:10:00.974995Z
18
yuanxch
1340
2048
dir
index.php
file
2014-05-20T06:26:13.000000Z
32fbd2e23aae0ea9a104605406c32598
2014-05-08T10:10:00.974995Z
18
yuanxch
1815
test.jpg
file
2014-05-08T10:06:29.000000Z
ae4864f8040b3deae2418351eaa23fcb
2014-05-08T10:10:00.974995Z
18
yuanxch
has-props
54108
oms
dir
favicon.ico
file
2014-05-08T10:05:29.000000Z
17dd153f10c6a1761f1d73145b50b642
2014-05-08T10:10:00.974995Z
18
yuanxch
has-props
12118
socket.io
dir
swf
dir
testcode.php
file
2014-05-08T10:06:28.000000Z
14422a3b87d68641a76a14adebcf65ca
2014-05-08T10:10:00.974995Z
18
yuanxch
659
sms
dir
tms
dir
min2
dir
xhprof
dir
data
dir
404.html
file
2014-05-08T10:05:05.000000Z
b0c2d9485858740a74b33d1427fa4e87
2014-05-08T10:10:00.974995Z
18
yuanxch
8993
index.html
file
2014-05-08T10:05:29.000000Z
d41d8cd98f00b204e9800998ecf8427e
2014-05-08T10:10:00.974995Z
18
yuanxch
0
tool
dir
user
dir


http://daxue.imooc.com/tms/
http://daxue.imooc.com/sms
http://daxue.imooc.com/cms
http://daxue.imooc.com/oms

漏洞证明:

33a.png


修复方案:

版权声明:转载请注明来源 Summer@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2014-11-22 14:58

厂商回复:

最新状态:

2015-01-01:漏洞已经修复了。