FTGate网界面服务器路径遍历漏洞

FTGate网界面服务器路径遍历漏洞

漏洞ID 1105459 漏洞类型 未知
发布时间 1999-05-25 更新时间 2005-05-02
图片[1]-FTGate网界面服务器路径遍历漏洞-安全小百科CVE编号 CVE-1999-0887
图片[2]-FTGate网界面服务器路径遍历漏洞-安全小百科CNNVD-ID CNNVD-199911-016
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/19223
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199911-016
|漏洞详情
FTGate界面服务器存在漏洞。远程攻击者可以通过一个..(点点)攻击读取文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/280/info

A vulnerability in Floosietek's FTGate allows remote malicious users to steal local files.

Floosietek's FTGate is a Win32 mail server program. One of its features is allowing administrators to check the status of the mail server using a web browser via a built-in web server.

The web server fails to check whether requested files fall outside its document tree (by using ".." in the URL). Thus attackers can retrieve files in the same drives as that on which the software resides if they know or can get it's filename. 

http://www.example.com:8080/../newuser.txt
|参考资料

来源:OSVDB
名称:1137
链接:http://www.osvdb.org/1137
来源:EEYE
名称:AD05261999
链接:http://www.eeye.com/html/Research/Advisories/AD05261999.html

相关推荐: Derek Leung pSlash Remote Arbitrary Code Execution Vulnerability

Derek Leung pSlash Remote Arbitrary Code Execution Vulnerability 漏洞ID 1102862 漏洞类型 Design Error 发布时间 2001-10-02 更新时间 2001-10-02 CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享