Wolfram Research webMathematica文件泄露漏洞

漏洞信息详情

Wolfram Research webMathematica文件泄露漏洞

漏洞简介

Wolfram Research webMathematica 1.0.0和1.0.0.1版本存在目录遍历漏洞。远程攻击者可以借助MSPStoreID参数中的一个..(点 点)读取任意文件。

漏洞公告

Reportedly, Wolfram Research has resolved this issue in the current version of webMathematica. Customers are advised to contact Wolfram Research for update information.

参考网址

来源:US-CERT Vulnerability Note: VU#664323
名称: VU#664323
链接:http://www.kb.cert.org/vuls/id/664323

来源: BID
名称: 5035
链接:http://www.securityfocus.com/bid/5035

来源: XF
名称: webmathematica-dot-directory-traversal(9373)
链接:http://www.iss.net/security_center/static/9373.php

来源: support.wolfram.com
链接:http://support.wolfram.com/webmathematica/security/fileaccess.html

来源: BUGTRAQ
名称: 20020617 Directory Traversal in Wolfram Research’s webMathematica
链接:http://archives.neohapsis.com/archives/bugtraq/2002-06/0174.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享