GoAhead Web Server目录遍历漏洞

GoAhead Web Server目录遍历漏洞

漏洞ID 1106843 漏洞类型 路径遍历
发布时间 2002-07-10 更新时间 2002-07-23
图片[1]-GoAhead Web Server目录遍历漏洞-安全小百科CVE编号 CVE-2002-0680
图片[2]-GoAhead Web Server目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200207-085
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21607
https://www.securityfocus.com/bid/89464
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200207-085
|漏洞详情
GoAheadWebServer2.1版本存在目录遍历漏洞。远程攻击者可以借助在..(点点)序列中带有编码的/(%5C)的URL读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/5197/info

A vulnerability has been reported for GoAhead WebServer 2.1. Reportedly, it is possible to launch directory traversal attacks against GoAhead WebServer. It is possible for remote attackers to access arbitrary files residing on a vulnerable host.

It has been reported that it is possible to exploit this vulnerability to access arbitrary files on the server through a directory traversal attack. GoAhead WebServer correctly prevents attackers from using '../' sequences for directory traversal attacks. However, it does not prevent attackers from using URL encoded substitutions for the '/' character.

** Orange Web Server 2.1 is based upon GoAhead WebServer. It has been reported that Orange Web Server 2.1 is also vulnerable to this issue.

** It is also possible to connect directly to a GoAhead WebServer using netcat or telnet and issuing a GET command for a known file using regular directory traversal sequences. There is no requirement for encoding the '/' character as '%5C'. Instead an attacker can obtain files by using '....' sequences.

GoAhead-server/..%5C..%5C..%5C..%5C..%5C..%5C/winnt/win.ini
|受影响的产品
Orange Software Orange Web Server 2.1

MontaVista Software Hard Hat Linux 1.0

GoAhead Software GoAhead WebServer 2.1.5

GoAhead Software GoAhead WebServer 2.1.4

GoAhead Software GoAhead Web

|参考资料

来源:VULNWATCH
名称:20020710[VulnWatch]wp-02-0001:GoAheadWebServerDirectoryTraversal+CrossSiteScripting
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0013.html
来源:BUGTRAQ
名称:20020719Re:[VulnWatch]wp-02-0001:GoAheadWebServerDirectoryTraversal+CrossSiteScripting
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=102709382714597&w;=2
来源:BUGTRAQ
名称:20020710wp-02-0001:GoAheadWebServerDirectoryTraversal+CrossSiteScripting
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=102631742711795&w;=2

相关推荐: Multiple Vendor Predictable Resolver ID Vulnerability

Multiple Vendor Predictable Resolver ID Vulnerability 漏洞ID 1104169 漏洞类型 Design Error 发布时间 2000-05-03 更新时间 2000-05-03 CVE编号 N/A CNN…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享