Extent RBS ISP web服务器目录遍历漏洞

Extent RBS ISP web服务器目录遍历漏洞

漏洞ID 1106010 漏洞类型 路径遍历
发布时间 2000-09-21 更新时间 2005-05-02
图片[1]-Extent RBS ISP web服务器目录遍历漏洞-安全小百科CVE编号 CVE-2000-1036
图片[2]-Extent RBS ISP web服务器目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200012-037
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/20234
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200012-037
|漏洞详情
ExtentRBSISPweb服务器存在目录遍历漏洞。远程攻击者借助对Image参数的..(点点)攻击读取敏感信息。
|漏洞EXP
source: http://www.securityfocus.com/bid/1704/info

A remote user is capable of gaining read access to any file residing in the same directory of a host running Extent RBS ISP through directory traversal. Appending '../' to the 'image' variable request on port 8002 will enable a user to read any available file includeing credit card details, username, password etc.

For example:

http://target:8002/Newuser?Image=../../database/rbsserv.mdb
|参考资料

来源:XF
名称:rbs-isp-directory-traversal
链接:http://xforce.iss.net/static/5275.php
来源:BID
名称:1704
链接:http://www.securityfocus.com/bid/1704
来源:BUGTRAQ
名称:20000920ExtentRBSdirectoryTransversal.
链接:http://archives.neohapsis.com/archives/bugtraq/2000-09/0252.html

相关推荐: Microsoft Windows File Protection Code-Signing Verification Weakness

Microsoft Windows File Protection Code-Signing Verification Weakness 漏洞ID 1101105 漏洞类型 Design Error 发布时间 2002-12-26 更新时间 2002-12-2…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享