Alstrasoft EPay Pro Index.PHP目录遍历漏洞

Alstrasoft EPay Pro Index.PHP目录遍历漏洞

漏洞ID 1109083 漏洞类型 路径遍历
发布时间 2005-09-19 更新时间 2005-10-20
图片[1]-Alstrasoft EPay Pro Index.PHP目录遍历漏洞-安全小百科CVE编号 CVE-2005-3026
图片[2]-Alstrasoft EPay Pro Index.PHP目录遍历漏洞-安全小百科CNNVD-ID CNNVD-200509-200
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/26272
https://cxsecurity.com/issue/WLB-2005090011
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200509-200
|漏洞详情
AlstrasoftEpayPro是一款处理在线业务的商业程序。AlstrasoftEpayPro2.0和早期版本中的index.php中存在目录遍历漏洞,远程攻击者可以通过read参数中的..(参数中包含’..’)读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/14871/info

EPay Pro is prone to a directory traversal vulnerability. This is due to a lack of proper validation of user-supplied input.

An unauthorized user can retrieve arbitrary files by supplying directory traversal strings '../' to the vulnerable parameter. Exploitation of this vulnerability could lead to a loss of confidentiality. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.

http://www.example.com/index.php?read=../../../../../../../../../../../../../../etc/passwd
|参考资料

来源:XF
名称:alstrasoft-epay-index-directory-traversal(22313)
链接:http://xforce.iss.net/xforce/xfdb/22313
来源:BID
名称:14871
链接:http://www.securityfocus.com/bid/14871
来源:MISC
链接:http://www.h4cky0u.org/advisories/HYA-2005-008-alstrasoft-epay-pro.txt
来源:BUGTRAQ
名称:20050918AlstrasoftEpayPro2.0andpriorDirectoryTraversalVulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112716394925851&w;=2
来源:BUGTRAQ
名称:20050919AlstrasoftEpayPro2.0andpriorDirectoryTraversalVulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112714879101323&w;=2
来源:FULLDISC
名称:20050918AlstrasoftEpayPro2.0andpriorDirectoryTraversalVulnerability
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2005-September/037225.html
来源:SREASON
名称:13
链接:http://securityreason.com/securityalert/13

相关推荐: PHP-Nuke CookieDecode Cross-Site Scripting Vulnerability

PHP-Nuke CookieDecode Cross-Site Scripting Vulnerability 漏洞ID 1098619 漏洞类型 Input Validation Error 发布时间 2004-04-13 更新时间 2004-04-13 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享