Hosting Controller browse.asp漏洞

Hosting Controller browse.asp漏洞

漏洞ID 1106733 漏洞类型 未知
发布时间 2002-05-19 更新时间 2002-08-12
图片[1]-Hosting Controller browse.asp漏洞-安全小百科CVE编号 CVE-2002-0775
图片[2]-Hosting Controller browse.asp漏洞-安全小百科CNNVD-ID CNNVD-200208-179
漏洞平台 ASP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21464
https://www.securityfocus.com/bid/89529
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200208-179
|漏洞详情
HostingControllerbrowse.asp存在漏洞。远程攻击者可以指定FilePath参数的目标路径名浏览任意目录。
|漏洞EXP
source: http://www.securityfocus.com/bid/4778/info

Hosting Controller is an application which consolidates all hosting tasks into one interface. Hosting Controller runs on Microsoft Windows operating systems.

The 'browse.asp' script is prone to an issue which may allow a remote attacker to view the contents of arbitrary files and directories. The attacker must provide a malicious value as a URL parameter in a request for the affected script, which will be read with the privileges of the web server process. 

http://target/admin/browse.asp?FilePath=c:&Opt=2&level=0
|受影响的产品
Hosting Controller Hosting Controller 1.4B

Hosting Controller Hosting Controller 1.4.1

Hosting Controller Hosting Controller 1.4

Hosting Controller Hosting Controller 1.3

Hosting Controll

|参考资料

来源:hostingcontroller.com
链接:http://hostingcontroller.com/english/logs/sp2log.html
来源:www.hostingcontroller.com
链接:http://www.hostingcontroller.com/english/patches/ForAll/download/drivebrowse.zip
来源:BUGTRAQ
名称:20020519Anothervulnerabilityinhostingcontroller
链接:http://archives.neohapsis.com/archives/bugtraq/2002-05/0168.html

相关推荐: Red Hat Linux Linuxconf服务拒绝漏洞

Red Hat Linux Linuxconf服务拒绝漏洞 漏洞ID 1207004 漏洞类型 未知 发布时间 1999-06-30 更新时间 1999-06-30 CVE编号 CVE-1999-1348 CNNVD-ID CNNVD-199906-034 漏…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享