Web TalkBack.cgi方式目录遍历漏洞

漏洞信息详情

Web TalkBack.cgi方式目录遍历漏洞

漏洞简介

talkback.cgi程序存在目录遍历漏洞。远程攻击者可以借助article参数中的..(点 点)读取任意文件。

漏洞公告

Way to the Web has addressed this issue in TalkBack 1.2:
Way to the Web TalkBack 1.1

参考网址

来源: BID
名称: 2547
链接:http://www.securityfocus.com/bid/2547

来源: BUGTRAQ
名称: 20010409 talkback.cgi vulnerability may allow users to read any file
链接:http://archives.neohapsis.com/archives/bugtraq/2001-04/0128.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享