HP Web Jetadmin固件升级脚本远程文件上传漏洞

HP Web Jetadmin固件升级脚本远程文件上传漏洞

漏洞ID 1107825 漏洞类型 设计错误
发布时间 2004-03-24 更新时间 2005-10-20
图片[1]-HP Web Jetadmin固件升级脚本远程文件上传漏洞-安全小百科CVE编号 CVE-2004-1856
图片[2]-HP Web Jetadmin固件升级脚本远程文件上传漏洞-安全小百科CNNVD-ID CNNVD-200403-104
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23878
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200403-104
|漏洞详情
HPWebJetAdmin具有一个整合式的修改的ApacheWeb服务器。HPWebJetadmin包含的固件升级脚本存在问题,远程攻击者可以利用这个脚本上传任意文件到服务器。使用/plugins/hpjwja/script/devices_update_printer_fw_upload.htsHTS脚本,任何文件可上传到”target=”_blank”>https://victim:8443/plugins/hpjwja/firmware/printer/目录中,不过幸运的是这些目录没有执行权限,但是,这个脚本结合其他漏洞,可导致任意代码执行。
|漏洞EXP
source: http://www.securityfocus.com/bid/9971/info

HP Web Jetadmin is prone to an issue which may permit remote users to upload arbitrary files to the management server. 

This issue exists in the printer firmware update script. Given the ability to place arbitrary files on the server to an attacker-specified location, it may be possible to execute arbitrary code, though this will require exploitation of other known vulnerabilities, such as BID 9972 "HP Web Jetadmin setinfo.hts Script Directory Traversal Vulnerability".

Authentication, if it has been enabled, would be required to exploit this issue.

This issue was reported in HP Web Jetadmin version 7.5.2546 on a Windows platform. Other versions may be similarly affected.

https://www.example.com:8443/plugins/hpjwja/script/devices_update_printer_fw_upload.hts
|参考资料

来源:XF
名称:hp-jetadmin-file-upload(15605)
链接:http://xforce.iss.net/xforce/xfdb/15605
来源:BID
名称:9971
链接:http://www.securityfocus.com/bid/9971
来源:HP
名称:SSRT4700
链接:http://www.securityfocus.com/advisories/6492
来源:sh0dan.org
链接:http://sh0dan.org/files/hpjadmadv.txt
来源:BUGTRAQ
名称:20040324HPWebJetAdminvulnerabilities.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108016019623003&w;=2

相关推荐: Ultimate PHP Board Add.PHP Path Disclosure Vulnerability

Ultimate PHP Board Add.PHP Path Disclosure Vulnerability 漏洞ID 1101207 漏洞类型 Failure to Handle Exceptional Conditions 发布时间 2002-12-0…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享