webMethods Glue ‘Console’目录遍历漏洞

漏洞信息详情

webMethods Glue ‘Console’目录遍历漏洞

漏洞简介

webMethods Glue的管理控制台中的/console存在目录遍历漏洞。远程攻击者可以借助资源参数中的..,读取任意的系统文件。

参考网址

来源: VUPEN

名称: ADV-2007-1363

链接:http://www.frsirt.com/english/advisories/2007/1363

来源: BID

名称: 23423

链接:http://www.securityfocus.com/bid/23423

来源: BUGTRAQ

名称: 20070507 Updated: webMethods Security Advisory: Glue console directory traversal vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/467873/30/6720/threaded

来源: BUGTRAQ

名称: 20070411 webMethods Glue Management Console Directory Traversal

链接:http://www.securityfocus.com/archive/1/archive/1/465332/100/0/threaded

来源: MISC

名称: http://www.aushack.com/advisories/200704-webmethods.txt

链接:http://www.aushack.com/advisories/200704-webmethods.txt

来源: SECTRACK

名称: 1017926

链接:http://www.securitytracker.com/id?1017926

来源: BUGTRAQ

名称: 20070417 webMethods Security Advisory: Glue console directory traversal vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/465993/100/0/threaded

来源: SREASON

名称: 2589

链接:http://securityreason.com/securityalert/2589

来源: SECUNIA

名称: 24933

链接:http://secunia.com/advisories/24933

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享