Abyss Web Server编码反斜杠目录遍历漏洞

漏洞信息详情

Abyss Web Server编码反斜杠目录遍历漏洞

漏洞简介

Abyss Web Server 1.0.3版本存在目录遍历漏洞。远程攻击者借助HTTP GET请求的..\ (点 点 反斜杠)序列读取任意文件。

漏洞公告

The vendor has released a patch for this issue. Users are advised to apply the patch or download a newer version of Abyss Web Server 1.0.3 with patches already applied:
Aprelium Technologies Abyss Web Server 1.0

Aprelium Technologies Abyss Web Server 1.0.3

参考网址

来源: XF
名称: abyss-get-directory-traversal(9941)
链接:http://www.iss.net/security_center/static/9941.php

来源: XF
名称: abyss-http-directory-traversal(9940)
链接:http://www.iss.net/security_center/static/9940.php

来源: www.aprelium.com
链接:http://www.aprelium.com/news/patch1033.html

来源: BID
名称: 5547
链接:http://www.securityfocus.com/bid/5547

来源: OSVDB
名称: 3285
链接:http://www.osvdb.org/3285

来源: BUGTRAQ
名称: 20020822 Abyss 1.0.3 directory traversal and administration bugs
链接:http://archives.neohapsis.com/archives/bugtraq/2002-08/0229.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享