VocalTec VGW4/8 Telephony Gateway远程认证绕过漏洞

VocalTec VGW4/8 Telephony Gateway远程认证绕过漏洞

漏洞ID 1107794 漏洞类型 设计错误
发布时间 2004-03-15 更新时间 2005-10-20
图片[1]-VocalTec VGW4/8 Telephony Gateway远程认证绕过漏洞-安全小百科CVE编号 CVE-2004-1813
图片[2]-VocalTec VGW4/8 Telephony Gateway远程认证绕过漏洞-安全小百科CNNVD-ID CNNVD-200412-427
漏洞平台 ASP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/23813
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-427
|漏洞详情
VocalTecVGW4/8Gateway8.0版本存在漏洞。远程攻击者可以借助到带有拖尾斜杠(/)的home.asp的HTTP请求绕过认证。
|漏洞EXP
source: http://www.securityfocus.com/bid/9876/info

It has been reported that the VGW4/8 Telephony Gateway is prone to a remote authentication bypass vulnerability via its web configuration tool. The problem is due to a design error in the application that allows a user to access configuration pages without prior authentication.

Successful exploitation of this issue may allow a remote attacker to gain control of the affected appliance via its web configuration tool.

http://www.example.com/home.asp/
http://www.example.com/home.asp/../menu.asp
|参考资料

来源:XF
名称:vgw48-gateway-directory-traversal(15476)
链接:http://xforce.iss.net/xforce/xfdb/15476
来源:BUGTRAQ
名称:20040315VocalTecGateway8ReverseDirectoryTransversal+AuthorizationBypass
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107936739131657&w;=2
来源:BID
名称:9876
链接:http://www.securityfocus.com/bid/9876

相关推荐: Secure Authentication Bypass Vulnerability

Secure Authentication Bypass Vulnerability 漏洞ID 1102196 漏洞类型 Design Error 发布时间 2002-04-17 更新时间 2002-04-17 CVE编号 N/A CNNVD-ID N/A 漏…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享