Roundup远程文件泄漏漏洞

漏洞信息详情

Roundup远程文件泄漏漏洞

漏洞简介

Roundup 0.6.4及其早期版本存在目录遍历漏洞。远程攻击者可以借助HTTP GET请求中的@@命令的..(点 点)序列浏览任意文件。

漏洞公告

Gentoo has released an advisory (GLSA 200408-09) to provide updates. Updates may be applied with the following commands:
emerge sync
emerge -pv “>=net-www/roundup-0.7.6”
emerge “>=net-www/roundup-0.7.6”
Roundup version 0.7.3 is available to address this issue:
Roundup Roundup 0.5

Roundup Roundup 0.5.1

Roundup Roundup 0.5.2

Roundup Roundup 0.5.3

Roundup Roundup 0.5.4

Roundup Roundup 0.5.5

Roundup Roundup 0.5.6

Roundup Roundup 0.5.7

Roundup Roundup 0.5.8 Stable

Roundup Roundup 0.5.9

Roundup Roundup 0.6.11

参考网址

来源: BID
名称: 10495
链接:http://www.securityfocus.com/bid/10495

来源: GENTOO
名称: GLSA-200408-09
链接:http://www.gentoo.org/security/en/glsa/glsa-200408-09.xml

来源: SECUNIA
名称: 11801
链接:http://secunia.com/advisories/11801/

来源: XF
名称: roundup-get-view-file(16350)
链接:http://xforce.iss.net/xforce/xfdb/16350

来源: SECTRACK
名称: 1010415
链接:http://securitytracker.com/id?1010415

来源: packetstormsecurity.nl
链接:http://packetstormsecurity.nl/0406-exploits/roundUP.txt

来源: sourceforge.net
链接:http://sourceforge.net/tracker/index.php?func=detail&aid=961511&group_id=31577&atid=402788

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享