Apple At Ease 5.0 – Information Disclosure

Apple At Ease 5.0 – Information Disclosure

漏洞ID 1053394 漏洞类型
发布时间 1999-05-13 更新时间 1999-05-13
图片[1]-Apple At Ease 5.0 – Information Disclosure-安全小百科CVE编号 N/A
图片[2]-Apple At Ease 5.0 – Information Disclosure-安全小百科CNNVD-ID N/A
漏洞平台 OSX CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/19427
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/531/info

At Ease 5.0 will allow a user to access any user's volume on the server through a web browser.

The tested configuration is as follows:

MacOS 7.6.1 (should work with anything greater than 7)
At Ease 5.0.2
AppleShare IP 5.0.3
Netscape 4.0.7 (No reason it shouldn't work from .99 to 4.5)

Log in as any user that has access to Netscape Communicator, and type in
f i l e://Macintosh%20HD/System%20Folder/
and you are able to access the disk.

Do the same thing, except use
f i l e://At%20Ease%20Volume%20Name/At%20Ease%20%Docs/username
and it's quite easy to browse through anyones files.

It is possible to download files from that users directory. I have been unable to actually open any of the files once they are downloaded, however in an educational setting, just viewing names in a certian directory could constitute some serious problems (such as if a teacher works with Special Education studends, and has a list of documents to their parents).

相关推荐: NT IMail Whois32 Daemon Buffer Overflow DoS Vulnerability

NT IMail Whois32 Daemon Buffer Overflow DoS Vulnerability 漏洞ID 1104838 漏洞类型 Boundary Condition Error 发布时间 1999-03-01 更新时间 1999-03-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享