Newsgrab 0.5.0pre4 – Multiple Local/Remote Vulnerabilities

Newsgrab 0.5.0pre4 – Multiple Local/Remote Vulnerabilities

漏洞ID 1108430 漏洞类型
发布时间 2005-02-02 更新时间 2005-02-02
图片[1]-Newsgrab 0.5.0pre4 – Multiple Local/Remote Vulnerabilities-安全小百科CVE编号 CVE-2005-0153
图片[2]-Newsgrab 0.5.0pre4 – Multiple Local/Remote Vulnerabilities-安全小百科CNNVD-ID N/A
漏洞平台 Linux CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/25080
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/12428/info

Newsgrab is reported prone to multiple vulnerabilities. The following individual issues are reported:

Newsgrab is reported prone to a directory traversal vulnerability. This vulnerability exists because the software does not sufficiently sanitize directory traversal sequences from filenames before the filename is employed to store the file onto disk.

A remote attacker may exploit this vulnerability by supplying a malicious file to a target victim. This vulnerability has been assigned the CVE identifier CAN-2005-0153.

Newsgrab is reported prone to an unspecified insecure permissions vulnerability.

A local attacker may exploit this vulnerability to disclose potentially sensitive information that is contained in files that were downloaded using newsgrab. This vulnerability has been assigned the CVE identifier CAN-2005-0154. 

A file containing the name '../../../../etc/rc.local' and the mode 777 could cause newsgrab to drop the file at /etc/rc.local with 777 permissions.

相关推荐: Microsoft Outlook Express 6.0 – Remote Denial of Service

Microsoft Outlook Express 6.0 – Remote Denial of Service 漏洞ID 1054445 漏洞类型 发布时间 2004-04-14 更新时间 2004-04-14 CVE编号 N/A CNNVD-ID N/A …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享