Singapore Image Gallery多个远程漏洞

漏洞信息详情

Singapore Image Gallery多个远程漏洞

漏洞简介

singapore Image Gallery Web Application 0.9.10存在多个目录遍历漏洞。远程攻击者可以(1)通过thumb.php中的showThumb类函数读取任意文件,或者(2)通过admin.class.php删除任意文件。

漏洞公告

The vendor has released singapore 0.9.11 beta to address these issues:
singapore singapore 0.9 a beta

singapore singapore 0.9 beta

singapore singapore 0.9.1 beta

singapore singapore 0.9.10

singapore singapore 0.9.10 beta

singapore singapore 0.9.2 beta

singapore singapore 0.9.3 beta

singapore singapore 0.9.4 beta

singapore singapore 0.9.5 beta

singapore singapore 0.9.6 beta

singapore singapore 0.9.7 beta

singapore singapore 0.9.8 beta

singapore singapore 0.9.9 a beta

singapore singapore 0.9.9 b beta

参考网址

来源: BID
名称: 11990
链接:http://www.securityfocus.com/bid/11990

来源: XF
名称: singapore-adminclass-directory-traversal(18532)
链接:http://xforce.iss.net/xforce/xfdb/18532

来源: XF
名称: singapore-thumb-directory-traversal(18528)
链接:http://xforce.iss.net/xforce/xfdb/18528

来源: www.security.org.sg
链接:http://www.security.org.sg/vuln/singapore0910.html

来源: BUGTRAQ
名称: 20041216 [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110323479715051&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享