EasyWeb FileManager模块目录遍历漏洞

EasyWeb FileManager模块目录遍历漏洞

漏洞ID 1108080 漏洞类型 路径遍历
发布时间 2004-07-23 更新时间 2005-10-20
图片[1]-EasyWeb FileManager模块目录遍历漏洞-安全小百科CVE编号 CVE-2004-2047
图片[2]-EasyWeb FileManager模块目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200407-039
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/24306
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200407-039
|漏洞详情
PostNuke的EasyWebFileManager1.0RC-1版本存在目录遍历漏洞。远程攻击者借助pathext参数的..(点点)检索任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/10792/info

EasyWeb is prone to a directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data. The issue occurs if a remote attacker sends a request to the 'ew_filemanager' script for a file containing directory traversal character sequences to the application.

EasyWeb FileManager 1.0 RC-1 is prone to this issue.

Update: Conflicting reports suggest that this issue may not be a vulnerability as access to various files can be limited by an EasyWeb administrator. An attacker with valid account credentials may only be able to carry out an attack. This BID will be updated as more information becomes available.

/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc

/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc/&view=passwd
|参考资料

来源:XF
名称:filemanager-pathext-view-directory-traversal(16806)
链接:http://xforce.iss.net/xforce/xfdb/16806
来源:BID
名称:10792
链接:http://www.securityfocus.com/bid/10792
来源:OSVDB
名称:8193
链接:http://www.osvdb.org/8193
来源:www.cirt.net
链接:http://www.cirt.net/advisories/ew_file_manager.shtml
来源:SECUNIA
名称:12151
链接:http://secunia.com/advisories/12151
来源:BUGTRAQ
名称:20040724EasyWebFileManagerDirectoryTraversal
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109068482605241&w;=2

相关推荐: BrowseFTP Client缓冲区溢出漏洞

BrowseFTP Client缓冲区溢出漏洞 漏洞ID 1106561 漏洞类型 缓冲区溢出 发布时间 2002-01-04 更新时间 2005-10-20 CVE编号 CVE-2002-2026 CNNVD-ID CNNVD-200212-342 漏洞平台…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享