ModLogAn Splitby输入验证漏洞

漏洞信息详情

ModLogAn Splitby输入验证漏洞

漏洞简介

当同时使用splitby时,ModLogAn 0.5.0到0.7.11版本processor_web plugin存在漏洞。本地用户借助符号链接攻击在日志文件中指定主机名的文件覆盖任意文件。

漏洞公告

The vendor has released an upgrade which addresses this issue. Users are also advised to investigate the fix information for BugTraq ID 3596 “Apache Split-Logfile File Append Vulnerability”, since exploitation of this issue is conditional upon other vulnerabilities.
ModLogAn ModLogAn 0.5

ModLogAn ModLogAn 0.5.6

ModLogAn ModLogAn 0.5.7

ModLogAn ModLogAn 0.6

ModLogAn ModLogAn 0.7.11

参考网址

来源: BID
名称: 3821
链接:http://www.securityfocus.com/bid/3821

来源: XF
名称: modlogan-splitby-symlink(7848)
链接:http://www.iss.net/security_center/static/7848.php

来源: jan.kneschke.de
链接:http://jan.kneschke.de/projects/modlogan/download/ChangeLog

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享