Xedus Webserver多个安全漏洞

Xedus Webserver多个安全漏洞

漏洞ID 1108205 漏洞类型 设计错误
发布时间 2004-09-30 更新时间 2005-10-20
图片[1]-Xedus Webserver多个安全漏洞-安全小百科CVE编号 CVE-2004-1646
图片[2]-Xedus Webserver多个安全漏洞-安全小百科CNNVD-ID CNNVD-200408-232
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/24419
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200408-232
|漏洞详情
Xedus是一款点对点WEB服务程序,提供多种资源的共享。Xedus存在多个安全问题,远程攻击者可以利用这些漏洞对服务程序进行拒绝服务攻击,跨站脚本攻击,及目录遍历攻击。具体问题如下:1.拒绝服务XedusWEB服务器在处理来自同一主机的多个连接时存在问题,会导致拒绝所有合法用户的访问。2.跨站脚本攻击XedusWEB服务器多个脚本不正确处理用户提交输入,攻击者可以提交恶意站点,诱使用户处理,导致敏感信息泄露。3.目录遍历攻击提交包含多个’../’字符的数据,可绕过WEBROOT限制,以WEB进程权限查看系统文件内容。
|漏洞EXP
source: http://www.securityfocus.com/bid/11071/info
  
It is reported that Xedus is susceptible to multiple vulnerabilities.
  
The first reported issue is a denial of service vulnerability. The affected application is unable to service multiple simultaneous connections, denying access to the hosted site for legitimate users.
  
The second reported issue is a cross-site scripting vulnerability in included sample scripts. This vulnerability is due to a failure of the application to properly sanitize user-supplied URI input before including it in the output of the scripts.
  
The third reported issue is a directory traversal vulnerability. The affected application will reportedly serve documents located outside of the configured web root. This may allow an attacker the ability to read arbitrary, potentially sensitive files on the hosting computer with the privileges of the web server. This may aid malicious users in further attacks.
  
These vulnerabilities are reported to exist in version 1.0 of Xedus.

http://www.example.com:4274/../data/log.txt
http://www.example.com:4274/../../../../../boot.ini
|参考资料

来源:XF
名称:xedus-dotdot-directory-traversal(17167)
链接:http://xforce.iss.net/xforce/xfdb/17167
来源:BID
名称:11071
链接:http://www.securityfocus.com/bid/11071
来源:www.gulftech.org
链接:http://www.gulftech.org/?node=research&article;_id=00047-08302004
来源:SECUNIA
名称:12418
链接:http://secunia.com/advisories/12418
来源:BUGTRAQ
名称:20040830MultipleVulnerabilitiesInXedusWebserver
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109394018411394&w;=2

相关推荐: PHPList Admin Page SQL Injection Vulnerability

PHPList Admin Page SQL Injection Vulnerability 漏洞ID 1096270 漏洞类型 Input Validation Error 发布时间 2005-07-28 更新时间 2005-07-28 CVE编号 N/A …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享