Flowerfire Sawmill文件访问漏洞

漏洞信息详情

Flowerfire Sawmill文件访问漏洞

漏洞简介

SawMill 5.0.21版本CGI程序存在漏洞。远程攻击者通过列表rfcf参数文件可以读取任意文件的第一行,那些文件的内容SawMill试图解析配置命令。

漏洞公告

Flowerfire has upgraded their product free of charge to address this problem.
Flowerfire Sawmill 5.0.21

参考网址

来源: BUGTRAQ
名称: 20000626 sawmill5.0.21 old path bug & weak hash algorithm
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html

来源: BID
名称: 1402
链接:http://www.securityfocus.com/bid/1402

来源: BUGTRAQ
名称: 20000706 Patch for Flowerfire Sawmill Vulnerabilities Available
链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享