漏洞信息详情
Wolfram Research webMathematica文件泄露漏洞
- CNNVD编号:CNNVD-200210-075
- 危害等级: 中危
- CVE编号:
CVE-2002-0926
- 漏洞类型:
路径遍历
- 发布时间:
2002-10-04
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
wolfram_research - 漏洞来源:
.’);”>Discovered by “And… -
漏洞简介
Wolfram Research webMathematica 1.0.0和1.0.0.1版本存在目录遍历漏洞。远程攻击者可以借助MSPStoreID参数中的一个..(点 点)读取任意文件。
漏洞公告
Reportedly, Wolfram Research has resolved this issue in the current version of webMathematica. Customers are advised to contact Wolfram Research for update information.
参考网址
来源:US-CERT Vulnerability Note: VU#664323
名称: VU#664323
链接:http://www.kb.cert.org/vuls/id/664323
来源: BID
名称: 5035
链接:http://www.securityfocus.com/bid/5035
来源: XF
名称: webmathematica-dot-directory-traversal(9373)
链接:http://www.iss.net/security_center/static/9373.php
来源: support.wolfram.com
链接:http://support.wolfram.com/webmathematica/security/fileaccess.html
来源: BUGTRAQ
名称: 20020617 Directory Traversal in Wolfram Research’s webMathematica
链接:http://archives.neohapsis.com/archives/bugtraq/2002-06/0174.html