Sambar Server pagecount CGI script文件覆盖漏洞

Sambar Server pagecount CGI script文件覆盖漏洞

漏洞ID 1106441 漏洞类型 路径遍历
发布时间 2001-07-22 更新时间 2005-05-02
图片[1]-Sambar Server pagecount CGI script文件覆盖漏洞-安全小百科CVE编号 CVE-2001-1010
图片[2]-Sambar Server pagecount CGI script文件覆盖漏洞-安全小百科CNNVD-ID CNNVD-200107-166
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21026
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200107-166
|漏洞详情
SambarServer5.0beta5之前版本的pagecountCGIscript存在目录遍历漏洞。远程攻击者可以借助page参数的..(点点)攻击覆盖任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/3091/info

Sambar Server is a multi-threaded HTTP server for Microsoft Windows and Unix systems.

Sambar WWW Server is bundled with a sample script('pagecount') which creates temporary files on the host. However, it is possible for a remote attacker to craft a web request which will cause pagecount to overwrite existing files. Files attacked in this manner will be corrupted.

Loss of critical data and a denial of services may occur if system files are overwritten.

http://sambarserver/session/pagecount?page=index will create a file in Sambar temp directory with name 'index'

http://sambarserver/session/pagecount?page=../../../../../../autoexec.bat then the script will rewrite the first symbols of c:autoexec.bat with it's number.

So we are able to add some text to any file on the disk.
|参考资料

来源:XF
名称:sambar-pagecount-overwrite-files(6916)
链接:http://xforce.iss.net/static/6916.php
来源:BID
名称:3092
链接:http://www.securityfocus.com/bid/3092
来源:www.sambar.com
链接:http://www.sambar.com/security.htm
来源:BUGTRAQ
名称:20010721SambarWebServerpagecountexploitcode
链接:http://archives.neohapsis.com/archives/bugtraq/2001-07/0565.html

相关推荐: Divine Content Server Error Page Cross-Site Scripting Vulnerability

Divine Content Server Error Page Cross-Site Scripting Vulnerability 漏洞ID 1099444 漏洞类型 Input Validation Error 发布时间 2003-10-03 更新时间 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享