Entrust GetAccess文件泄露漏洞

漏洞信息详情

Entrust GetAccess文件泄露漏洞

漏洞简介

Entrust GetAccess存在目录遍历漏洞。远程攻击者可以借助locale参数中(1) helpwin.gas.bat,(2) AboutBox.gas.bat的一个..(点 点)读取任意文件。

漏洞公告

The vendor has patched the vulnerable scripts, and it should be applied by those users who wish to continuing using them. The patch can be found at:
https://login.encommerce.com/private/docs/techSupport/Patches-BugFix

参考网址

来源:US-CERT Vulnerability Note: VU#243243
名称: VU#243243
链接:http://www.kb.cert.org/vuls/id/243243

来源: BUGTRAQ
名称: 20011105 Entrust Bulletin E01-005: GetAccess Access Service vulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2001-11/0022.html

来源: XF
名称: getaccess-shellscripts-retrieve-files(7474)
链接:http://xforce.iss.net/xforce/xfdb/7474

来源: BID
名称: 3508
链接:http://www.securityfocus.com/bid/3508

来源: BUGTRAQ
名称: 20011105 New getAccess[tm] Vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=100498111712723&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享