mpnews pro 2.1.0.18 – Directory Traversal Information Disclosure

mpnews pro 2.1.0.18 – Directory Traversal Information Disclosure

漏洞ID 1054201 漏洞类型
发布时间 2003-10-01 更新时间 2003-10-01
图片[1]-mpnews pro 2.1.0.18 – Directory Traversal Information Disclosure-安全小百科CVE编号 N/A
图片[2]-mpnews pro 2.1.0.18 – Directory Traversal Information Disclosure-安全小百科CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/23208
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/8744/info

It has been reported that MPNews PRO is prone to an information disclosure vulnerability. The problem is believed to occur due to MPNews PRO failing to sufficiently filter specific dot-dot-slash sequences (../). As a result, an attacker may be capable of viewing the contents of files located outside of the established web root. 

http://www.example.org/./.././../mpnews.ini

相关推荐: Nortel Netgear ISDN RH348 and RT328 Denial Of Service Vulnerabilities

Nortel Netgear ISDN RH348 and RT328 Denial Of Service Vulnerabilities 漏洞ID 1104390 漏洞类型 Failure to Handle Exceptional Conditions 发…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享