Happymall E-Commerce Software Normal_HTML.CGI文件泄露漏洞

Happymall E-Commerce Software Normal_HTML.CGI文件泄露漏洞

漏洞ID 1107318 漏洞类型 路径遍历
发布时间 2003-05-12 更新时间 2005-10-20
图片[1]-Happymall E-Commerce Software Normal_HTML.CGI文件泄露漏洞-安全小百科CVE编号 CVE-2003-0277
图片[2]-Happymall E-Commerce Software Normal_HTML.CGI文件泄露漏洞-安全小百科CNNVD-ID CNNVD-200306-091
漏洞平台 CGI CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/22592
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200306-091
|漏洞详情
Happycgi.comHappymall4.3和4.4版本normal_html.cgi存在目录遍历漏洞。远程攻击者借助file参数的..(点点)序列读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/7559/info

IT has been reported that Happymall E-Commerce is prone to a file disclosure vulnerability. The problem occurs due to insufficient sanitization of user-supplied URI parameters. As a result, it may be possible for an attacker to view the contents of sensitive system files. Files viewed in this manner would be accessed with the privileges of the Happymall process. 

http://www.target.org/shop/normal_html.cgi?file=../../../../../../etc/issue%00
|参考资料

来源:XF
名称:happymall-dotdot-directory-traversal(11987)
链接:http://xforce.iss.net/xforce/xfdb/11987
来源:BID
名称:7559
链接:http://www.securityfocus.com/bid/7559
来源:BUGTRAQ
名称:20030512OnemoreflawinHappymall
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=105276130814262&w;=2

相关推荐: SCO OpenServer cancel Buffer Overflow Vulnerability

SCO OpenServer cancel Buffer Overflow Vulnerability 漏洞ID 1104565 漏洞类型 Boundary Condition Error 发布时间 1999-10-08 更新时间 1999-10-08 CVE…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享