漏洞信息详情
Novell NetWare Encoded Slash目录遍历漏洞
- CNNVD编号:CNNVD-200304-087
- 危害等级: 中危
- CVE编号:
CVE-2002-1437
- 漏洞类型:
路径遍历
- 发布时间:
2003-04-11
- 威胁类型:
远程
- 更新时间:
2005-10-12
- 厂 商:
novell - 漏洞来源:
Credited to Rain F… -
漏洞简介
Novell NetWare 5.1和NetWare 6版本中Perl 5.003的web处理器存在目录遍历漏洞。远程攻击者借助包含\”..\\%5c\” (URL-encoded 点-点 反斜线)序列的HTTP请求读取任意文件。
漏洞公告
An update is available:
Novell Netware 5.1 SP4
-
Novell perl5002.exeFree registration is required.
http://support.novell.com/servlet/filedownload/ftf/perl5002.exe/
Novell Netware 5.1
-
Novell perl5002.exeFree registration is required.
http://support.novell.com/servlet/filedownload/ftf/perl5002.exe/
Novell Netware 6.0
-
Novell perl5002.exeFree registration is required.
http://support.novell.com/servlet/filedownload/ftf/perl5002.exe/
Novell Netware 6.0 SP1
-
Novell perl5002.exeFree registration is required.
http://support.novell.com/servlet/filedownload/ftf/perl5002.exe/
参考网址
来源: BID
名称: 5522
链接:http://www.securityfocus.com/bid/5522
来源: XF
名称: netware-perl-directory-traversal(9915)
链接:http://www.iss.net/security_center/static/9915.php
来源: BUGTRAQ
名称: 20020820 NOVL-2002-2963307 – PERL Handler Vulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2002-08/0202.html
来源: support.novell.com
链接:http://support.novell.com/servlet/tidfinder/2963307
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END