Icecast目录遍历漏洞

Icecast目录遍历漏洞

漏洞ID 1106412 漏洞类型 路径遍历
发布时间 2001-06-26 更新时间 2005-05-02
图片[1]-Icecast目录遍历漏洞-安全小百科CVE编号 CVE-2001-0784
图片[2]-Icecast目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200110-062
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/20972
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200110-062
|漏洞详情
Icecast1.3.10及其早期版本存在目录遍历漏洞。远程攻击者借助使用已编码的URL字符修改过的..(点点)攻击读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/2932/info

Icecast is an open source audio-streaming server for both Unix and Microsoft Windows systems.

Icecast does not filter encoded characters from URLs when receiving web requests. If a remote attacker crafts a URL containing the ASCII equivalent of directory traversal characters, it is possible to escape Icecast's "root" directory. This will allow the attacker to view files readable by the ownership and group membership of the icecast server. 

Mp3-files residing outside the Web catalog can be accessed by replacing ascii-values for each ".", thus using "/%2E%2E/" instead of "/../" will walk one folder downward.

Place a mp3-file named "test1.mp3" in the directory below the one you specified in the variable "staticdir".

Then write the following in your browser:

http://localhost:8000/file/../test1.mp3 - Will fail in getting the file

http://localhost:8000/file/%2E%2E/test1.mp3 - Will succeed in getting the file
|参考资料

来源:BID
名称:2932
链接:http://www.securityfocus.com/bid/2932
来源:BUGTRAQ
名称:20010626Advisory
链接:http://archives.neohapsis.com/archives/bugtraq/2001-06/0353.html
来源:XF
名称:icecast-dot-directory-traversal(6752)
链接:http://xforce.iss.net/static/6752.php
来源:REDHAT
名称:RHSA-2002:063
链接:http://www.redhat.com/support/errata/RHSA-2002-063.html
来源:REDHAT
名称:RHSA-2001:105
链接:http://www.redhat.com/support/errata/RHSA-2001-105.html
来源:OSVDB
名称:1883
链接:http://www.osvdb.org/1883
来源:DEBIAN
名称:DSA-089
链接:http://www.debian.org/security/2001/dsa-089

相关推荐: CommuniGate Pro Webmail会话劫持漏洞

CommuniGate Pro Webmail会话劫持漏洞 漏洞ID 1107302 漏洞类型 信息泄露 发布时间 2003-05-05 更新时间 2003-12-31 CVE编号 CVE-2003-1481 CNNVD-ID CNNVD-200312-077…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享