SeaNox Devwex目录遍历漏洞

SeaNox Devwex目录遍历漏洞

漏洞ID 1106774 漏洞类型 路径遍历
发布时间 2002-06-08 更新时间 2005-05-02
图片[1]-SeaNox Devwex目录遍历漏洞-安全小百科CVE编号 CVE-2002-0946
图片[2]-SeaNox Devwex目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200210-209
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21530
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200210-209
|漏洞详情
SeaNoxDevwex1.2002.0601之前版本存在目录遍历漏洞。远程攻击者借助HTTP请求中的..(点点)序列读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/4978/info

The Seanox DevWex Windows binary version is prone to an issue which may cause arbitrary web-readable files to be disclosed to remote attackers. This problem occurs because DevWex does not sufficiently filter '..' sequences from web requests. 

GET /........anyfile
|参考资料

来源:BID
名称:4978
链接:http://www.securityfocus.com/bid/4978
来源:XF
名称:devwex-dotdot-directory-traversal(9299)
链接:http://www.iss.net/security_center/static/9299.php
来源:www.seanox.de
链接:http://www.seanox.de/projects.devwex.php
来源:OSVDB
名称:5048
链接:http://www.osvdb.org/5048
来源:BUGTRAQ
名称:20020608SeaNoxDevwex-DenialofServiceandDirectorytraversal
链接:http://archives.neohapsis.com/archives/bugtraq/2002-06/0056.html

相关推荐: Axis Communications Video Server 2.x – ‘Command.cgi’ File Creation

Axis Communications Video Server 2.x – ‘Command.cgi’ File Creation 漏洞ID 1053731 漏洞类型 发布时间 2003-02-28 更新时间 2003-02-28 CVE编号 N/A CNN…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享