NAI Net Tools PKI server文件泄露漏洞

NAI Net Tools PKI server文件泄露漏洞

漏洞ID 1105982 漏洞类型 路径遍历
发布时间 2000-08-02 更新时间 2005-05-02
图片[1]-NAI Net Tools PKI server文件泄露漏洞-安全小百科CVE编号 CVE-2000-0739
图片[2]-NAI Net Tools PKI server文件泄露漏洞-安全小百科CNNVD-ID CNNVD-200010-025
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/20135
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200010-025
|漏洞详情
NAINetToolsPKIserver1.0HotFix3之前的版本存在目录遍历漏洞。远程攻击者可以借助注册服务器HTTPS请求的..(点点)攻击读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/1537/info

Certain versions of Network Associates Inc.'s Net Tools PKI (Public Key Infrastructure) server ship with a vulnerability which allows remote attackers to read any file in the system which the PKI server resides. The problem lies within the webserver component of the PKI server (strong.exe) which operates several 'virtual servers' required to operate the PKI server. The first is the Administrative Web Server which listens via TCP port 443, the second is Enrollment Web Server which listens on TCP port 444. Unlike the Administrative Web Server the Enrollment Web Server does not require credentials to be exchanged before a user can talk to the webserver. It is via this virtual server that an attacker can exploit the problem at hand.

The problem in particular is a failure on behalf of the web server to enforce a web root directory. Therefore, a user may walk the entire directory tree of the target host and view files of which they know the locations. Autoexec.bat for example, backup SAM files etc.

By default the enrollment server uses Program FilesNetwork AssociatesNet Tools PKI ServerWebServerenroll-server as the Web Root directory. In a properly written webserver a user should only be able to move forward in the tree not backward.

https://host:444/..........autoexec.bat
|参考资料

来源:BID
名称:1537
链接:http://www.securityfocus.com/bid/1537
来源:download.nai.com
链接:http://download.nai.com/products/licensed/pgp/hf3pki10.txt
来源:BUGTRAQ
名称:20000802NAINetToolsPKIServervulnerabilities
链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html
来源:XF
名称:nettools-pki-dir-traverse(5066)
链接:http://xforce.iss.net/static/5066.php
来源:OSVDB
名称:1489
链接:http://www.osvdb.org/1489

相关推荐: CartWIZ 1.10 – ‘TellAFriend.asp’ Cross-Site Scripting

CartWIZ 1.10 – ‘TellAFriend.asp’ Cross-Site Scripting 漏洞ID 1055041 漏洞类型 发布时间 2005-04-23 更新时间 2005-04-23 CVE编号 N/A CNNVD-ID N/A 漏洞平…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享