BB4技术Big Brother目录遍历漏洞

漏洞信息详情

BB4技术Big Brother目录遍历漏洞

漏洞简介

Big Brother 1.4h1版本及之前版本中bb-hostsvc.sh存在漏洞。远程攻击者可以借助对HOSTSVC参数的..(点 点)攻击来读取任意文件。

漏洞公告

BB4 Technologies has released version 1.4H2 which is not susceptible to this vulnerability. It is available for download at the following location:
http://bb4.com/download.html

参考网址

来源: XF
名称: http-cgi-bigbrother-bbhostsvc
链接:http://xforce.iss.net/static/4879.php

来源: BID
名称: 1455
链接:http://www.securityfocus.com/bid/1455

来源: bb4.com
链接:http://bb4.com/README.CHANGES

来源: BUGTRAQ
名称: 20000711 REMOTE EXPLOIT IN ALL CURRENT VERSIONS OF BIG BROTHER
链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0147.html

来源: BUGTRAQ
名称: 20000711 BIG BROTHER EXPLOIT
链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0146.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享