Drummon Miles A1Stats目录遍历漏洞

Drummon Miles A1Stats目录遍历漏洞

漏洞ID 1106333 漏洞类型 路径遍历
发布时间 2001-05-07 更新时间 2005-10-20
图片[1]-Drummon Miles A1Stats目录遍历漏洞-安全小百科CVE编号 CVE-2001-0561
图片[2]-Drummon Miles A1Stats目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200108-062
漏洞平台 CGI CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/20832
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200108-062
|漏洞详情
DrummondMilesA1Stats1.6之前版本存在目录遍历漏洞。远程攻击者可以借助(1)a1disp2.cgi、(2)a1disp3.cgi或(3)a1disp4.cgi中的’..’(点点)攻击读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/2705/info
 
A1Stats is a CGI product by Drummon Miles used to report on a website's visitor traffic.
 
Versions of this product fail to properly validate user-supplied input submitted as querystrings to the A1Stats script.
 
An attacker can compose a long path including '/../' sequences, and submit it as a file request to the product's built-in webserver. 'dot dot' sequences will not be filtered from the path, permitting the attacker to specify files outside the directory tree normally available to users.
 
This can permit disclosure of confidential data and sensitive system files which, if properly exploited, could lead to further compromises of the host's security.
 
Additionally, by appending a properly formatted echo command argumented by a filename writable by the webserver, this flaw allows the attacker to overwrite this file with A1Stats' output.

www.server.com/cgi-bin/a1stats/a1disp3.cgi?../../../../../../../etc/passwd
|参考资料

来源:US-CERTVulnerabilityNote:VU#471691
名称:VU#471691
链接:http://www.kb.cert.org/vuls/id/471691
来源:XF
名称:a1stats-dot-directory-traversal(6503)
链接:http://xforce.iss.net/static/6503.php
来源:BUGTRAQ
名称:20010507AdvisoryforA1Stats
链接:http://archives.neohapsis.com/archives/bugtraq/2001-05/0047.html
来源:BID
名称:2705
链接:http://www.securityfocus.com/bid/2705

相关推荐: HP CDE程序根变量漏洞

HP CDE程序根变量漏洞 漏洞ID 1207000 漏洞类型 未知 发布时间 1999-07-01 更新时间 2005-05-02 CVE编号 CVE-1999-0690 CNNVD-ID CNNVD-199907-003 漏洞平台 N/A CVSS评分 7…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享