Deerfield WebSite Pro 8.3文件名源泄露漏洞

漏洞信息详情

Deerfield WebSite Pro 8.3文件名源泄露漏洞

漏洞简介

基于Windows的WebSite Pro 3.1.11.0版本存在漏洞。远程攻击者借助使用等效8.3文件名的
URL请求为扩展名超过3个字符文件名读取脚本源代码。

漏洞公告

The vendor has also released an upgrade which addresses this issue.
Deerfield.com WebSite 3.1.11 .0

参考网址

来源: BID
名称: 4783
链接:http://www.securityfocus.com/bid/4783

来源: XF
名称: website-pro-source-disclosure(9147)
链接:http://www.iss.net/security_center/static/9147.php

来源: BUGTRAQ
名称: 20020519 Multiple vendors web server source code disclosure (8.3 name format vulnerability – take II)
链接:http://archives.neohapsis.com/archives/bugtraq/2002-05/0178.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享