canvas.anubix.net PnTresMailer codebrowserpntm.php 目录遍历漏洞

canvas.anubix.net PnTresMailer codebrowserpntm.php 目录遍历漏洞

漏洞ID 1108308 漏洞类型 路径遍历
发布时间 2004-11-26 更新时间 2005-10-20
图片[1]-canvas.anubix.net PnTresMailer codebrowserpntm.php 目录遍历漏洞-安全小百科CVE编号 CVE-2004-1206
图片[2]-canvas.anubix.net PnTresMailer codebrowserpntm.php 目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200501-226
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/24783
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200501-226
|漏洞详情
PnTresMailer是一款Web界面的代码查看和下载程序。PnTresMailer6.0.3版本的codebrowserpntm.php存在目录遍历漏洞。远程攻击者可利用filetodownload参数,使用”..”方式,读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/11767/info

pnTresMailer is reported susceptible to a directory traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data.

This vulnerability can be exploited to retrieve arbitrary, potentially sensitive files from the hosting computer with the privileges of the web server. This may aid a malicious user in further attacks.

Version 6.03 of the application is reportedly affected by this vulnerability.

http://www.example.com/codebrowserpntm.php?downloadfolder=pnTresMailer&filetodownload=../../../../etc/passwd
|参考资料

来源:XF
名称:pntresmailer-information-disclosure(18263)
链接:http://xforce.iss.net/xforce/xfdb/18263
来源:BID
名称:11767
链接:http://www.securityfocus.com/bid/11767
来源:BUGTRAQ
名称:20041126PnTresMailercodebrowser6.03Vulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110149886306037&w;=2

相关推荐: Seyeon FlexWATCH Network Video Server未授权管理访问漏洞

Seyeon FlexWATCH Network Video Server未授权管理访问漏洞 漏洞ID 1107559 漏洞类型 访问验证错误 发布时间 2003-10-31 更新时间 2005-10-20 CVE编号 CVE-2003-1160 CNNVD-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享