Bharat Mediratta Gallery目录遍历漏洞

Bharat Mediratta Gallery目录遍历漏洞

漏洞ID 1106518 漏洞类型 路径遍历
发布时间 2001-11-19 更新时间 2005-05-20
图片[1]-Bharat Mediratta Gallery目录遍历漏洞-安全小百科CVE编号 CVE-2001-0900
图片[2]-Bharat Mediratta Gallery目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200111-015
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21157
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200111-015
|漏洞详情
Gallerybefore1.2.3版本的modules.php存在目录遍历漏洞。远程攻击者可以借助include参数的..(点点)读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/3554/info

Bharat Mediratta Gallery is a free, open source web-based photo album which may be used as an add-on for the PHPNuke web portal.

Due to insufficient validation of user-supplied input, it is be possible to view arbitrary web-readable files via a specially crafted web request which contains '../' sequences.

This issue may allow a remote attacker to gather sensitive information which may be used in directed and organized attacks against a host running the Gallery software.

http://www.somehost.com/modules.php?set_albumName=album01&id=aaw&op=modload&name=gallery&file=index&include=../../../../../../etc/hosts
|参考资料

来源:BUGTRAQ
名称:20011118GalleryAddonforPhpNukeremotefileviewingvulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=100619599000590&w;=2
来源:XF
名称:phpnuke-gallery-directory-traversal(7580)
链接:http://xforce.iss.net/xforce/xfdb/7580
来源:BID
名称:3554
链接:http://www.securityfocus.com/bid/3554
来源:OSVDB
名称:677
链接:http://www.osvdb.org/677

相关推荐: UseModWiki 1.0 – Wiki.pl Cross-Site Scripting

UseModWiki 1.0 – Wiki.pl Cross-Site Scripting 漏洞ID 1054797 漏洞类型 发布时间 2004-12-14 更新时间 2004-12-14 CVE编号 N/A CNNVD-ID N/A 漏洞平台 CGI CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享