Bytehoard文件泄露漏洞

Bytehoard文件泄露漏洞

漏洞ID 1107526 漏洞类型 路径遍历
发布时间 2003-10-20 更新时间 2003-12-31
图片[1]-Bytehoard文件泄露漏洞-安全小百科CVE编号 CVE-2003-1499
图片[2]-Bytehoard文件泄露漏洞-安全小百科CNNVD-ID CNNVD-200312-273
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23261
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-273
|漏洞详情
Bytehoard0.7版本的index.php存在目录遍历漏洞。远程攻击者借助infolder参数中的..(点点)读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/8850/info

Bytehoard is prone to directory traversal attacks. This could potentially permit remote attackers to gain unauthorized access to sensitive files hosted on the system running the software.

http://www.example.com/bytehoard/index.php?infolder=../../../../
|参考资料

来源:BID
名称:8850
链接:http://www.securityfocus.com/bid/8850
来源:XF
名称:bytehoard-dotdot-directory-traversal(13456)
链接:http://xforce.iss.net/xforce/xfdb/13456
来源:www.securiteam.com
链接:http://www.securiteam.com/unixfocus/6L00L008KE.html
来源:FULLDISC
名称:20031019ByteHoardDirectoryTraversalVulnerability
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/012430.html
来源:BUGTRAQ
名称:20031019ByteHoardDirectoryTraversalVulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2003-10/0200.html

相关推荐: PServ Web Server Directory Traversal Vulnerability

PServ Web Server Directory Traversal Vulnerability 漏洞ID 1099087 漏洞类型 Input Validation Error 发布时间 2003-12-22 更新时间 2003-12-22 CVE编号 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享