漏洞信息详情
Abyss Web Server编码反斜杠目录遍历漏洞
- CNNVD编号:CNNVD-200210-009
- 危害等级: 中危
- CVE编号:
CVE-2002-1079
- 漏洞类型:
路径遍历
- 发布时间:
2002-10-04
- 威胁类型:
远程
- 更新时间:
2005-05-02
- 厂 商:
aprelium_technologies - 漏洞来源:
Discovery of this … -
漏洞简介
Abyss Web Server 1.0.3版本存在目录遍历漏洞。远程攻击者借助HTTP GET请求的..\ (点 点 反斜杠)序列读取任意文件。
漏洞公告
The vendor has released a patch for this issue. Users are advised to apply the patch or download a newer version of Abyss Web Server 1.0.3 with patches already applied:
Aprelium Technologies Abyss Web Server 1.0
-
Aprelium Technologies abysswsLinux patch.
http://www.aprelium.com/data/patch1033/abyssws -
Aprelium Technologies abyssws.exeWindows patch.
http://www.aprelium.com/data/patch1033/abyssws.exe
Aprelium Technologies Abyss Web Server 1.0.3
-
Aprelium Technologies abysswsLinux patch.
http://www.aprelium.com/data/patch1033/abyssws -
Aprelium Technologies abyssws.exeWindows patch.
http://www.aprelium.com/data/patch1033/abyssws.exe
参考网址
来源: XF
名称: abyss-get-directory-traversal(9941)
链接:http://www.iss.net/security_center/static/9941.php
来源: XF
名称: abyss-http-directory-traversal(9940)
链接:http://www.iss.net/security_center/static/9940.php
来源: www.aprelium.com
链接:http://www.aprelium.com/news/patch1033.html
来源: BID
名称: 5547
链接:http://www.securityfocus.com/bid/5547
来源: OSVDB
名称: 3285
链接:http://www.osvdb.org/3285
来源: BUGTRAQ
名称: 20020822 Abyss 1.0.3 directory traversal and administration bugs
链接:http://archives.neohapsis.com/archives/bugtraq/2002-08/0229.html