RedHat Interchange远程泄漏任意文件漏洞

RedHat Interchange远程泄漏任意文件漏洞

漏洞ID 1106915 漏洞类型 未知
发布时间 2002-08-13 更新时间 2002-09-05
图片[1]-RedHat Interchange远程泄漏任意文件漏洞-安全小百科CVE编号 CVE-2002-0874
图片[2]-RedHat Interchange远程泄漏任意文件漏洞-安全小百科CNNVD-ID CNNVD-200209-012
漏洞平台 Linux CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21706
https://www.securityfocus.com/bid/89480
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200209-012
|漏洞详情
Interchange是一套电子商务和应用服务器系统。该系统可用于构建一个基于数据库的Web服务器以及在线应用。Interchange4.8.5以及更低版本中存在一个安全漏洞,当它运行在”INETmode”方式时,允许攻击者读取任意Interchange进程有权读取的文件,这可能泄漏给攻击者一些敏感信息,攻击者可能利用这些信息发动进一步攻击。
|漏洞EXP
source: http://www.securityfocus.com/bid/5453/info

A vulnerability has been reported for Interchange 4.8.5 and earlier. Reportedly, Interchange may disclose contents of files to attackers.

The vulnerability occurs due to the placement of the 'doc' folder. Reportedly, the folder will be installed as follows: <INTERCHANGE_ROOT>/doc. This folder, by default, contains Interchange man pages. This vulnerability is only exploitable when the Interchange service runs in INET (Internet service) mode.

An attacker may exploit this vulnerability to the contents of restricted files accessible to the Interchange process.

It has been reported that this issue may be exploited through a '../' directory traversal sequence in a HTTP request to the vulnerable server.

http://www.domain.com:7786/../../../../../../../../../etc/passwd
|受影响的产品
Redhat Interchange 4.8.5

Redhat Interchange 4.8.4

Redhat Interchange 4.8.3

+

Debian Linux 3.0

Redhat Interchange 4.8.2

Redhat Interchange

|参考资料

来源:DEBIAN
名称:DSA-150
链接:http://www.debian.org/security/2002/dsa-150

相关推荐: OpenWindows cmdtool和SunOS Xview L2/AGAIN密钥显示unechoed字符漏洞

OpenWindows cmdtool和SunOS Xview L2/AGAIN密钥显示unechoed字符漏洞 漏洞ID 1207329 漏洞类型 未知 发布时间 1998-07-15 更新时间 1998-07-15 CVE编号 CVE-1999-1297 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享