漏洞信息详情
Apache Tomcat WebDav远程信息泄露漏洞
- CNNVD编号:CNNVD-200710-294
- 危害等级: 低危
- CVE编号:
CVE-2007-5461
- 漏洞类型:
路径遍历
- 发布时间:
2007-05-16
- 威胁类型:
远程
- 更新时间:
2019-04-02
- 厂 商:
apache - 漏洞来源:
eliteb0y※ eliteb0y… -
漏洞简介
Apache Tomcat是一个流行的开放源码的JSP应用服务器程序。
如果将Apache Tomcat的WebDAV servlet配置为同上下文使用且允许写访问的话,则远程攻击者可以通过提交指定了SYSTEM标签的WebDAV请求导致泄露任意文件的内容。
参考网址
来源:SECUNIA
链接:http://secunia.com/advisories/28317
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2007/3671
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2007/3674
来源:MLIST
链接:http://mail-archives.apache.org/mod_mbox/tomcat-users/200710.mbox/%3C47135C2D.1000705@apache.org%3E
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2008/2823
来源:SECUNIA
链接:http://secunia.com/advisories/31493
来源:CONFIRM
链接:http://tomcat.apache.org/security-5.html
来源:SECTRACK
链接:http://www.securitytracker.com/id?1018864
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/28361
来源:BID
链接:http://www.securityfocus.com/bid/31681
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2008/2780
来源:APPLE
链接:http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
来源:SECUNIA
链接:http://secunia.com/advisories/30676
来源:CONFIRM
链接:http://geronimo.apache.org/2007/10/18/potential-vulnerability-in-apache-tomcat-webdav-servlet.html
来源:EXPLOIT-DB
链接:https://www.exploit-db.com/exploits/4530
来源:SECUNIA
链接:http://secunia.com/advisories/27398
来源:DEBIAN
链接:http://www.debian.org/security/2008/dsa-1453
来源:REDHAT
链接:http://www.redhat.com/support/errata/RHSA-2008-0195.html
来源:REDHAT
链接:http://www.redhat.com/support/errata/RHSA-2008-0042.html
来源:MISC
链接:http://issues.apache.org/jira/browse/GERONIMO-3549
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/30908
来源:MANDRIVA
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2007:241
来源:REDHAT
链接:http://www.redhat.com/support/errata/RHSA-2008-0261.html
来源:CONFIRM
链接:http://tomcat.apache.org/security-6.html
来源:MANDRIVA
链接:http://www.mandriva.com/security/advisories?name=MDVSA-2009:136
来源:MLIST
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2008/1981/references
来源:CONFIRM
链接:http://www-1.ibm.com/support/docview.wss?uid=swg21286112
来源:SECUNIA
链接:http://secunia.com/advisories/37460
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/57126
来源:CONFIRM
链接:http://support.apple.com/kb/HT3216
来源:CONFIRM
链接:http://www.vmware.com/security/advisories/VMSA-2008-0010.html
来源:GENTOO
链接:http://security.gentoo.org/glsa/glsa-200804-10.xml
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/507985/100/0/threaded
来源:HP
链接:http://marc.info/?l=bugtraq&m=139344343412337&w=2
来源:FULLDISC
链接:http://marc.info/?l=full-disclosure&m=119239530508382
来源:CONFIRM
链接:http://support.apple.com/kb/HT2163
来源:SECUNIA
链接:http://secunia.com/advisories/29242
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2009/3316
来源:SECUNIA
链接:http://secunia.com/advisories/27727
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/37243
来源:SECUNIA
链接:http://secunia.com/advisories/27446
来源:SECUNIA
链接:http://secunia.com/advisories/32120
来源:REDHAT
链接:http://www.redhat.com/support/errata/RHSA-2008-0862.html
来源:CONFIRM
链接:http://www.vmware.com/security/advisories/VMSA-2009-0016.html
来源:APPLE
链接:http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
来源:BID
链接:http://www.securityfocus.com/bid/26070
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2008/1979/references
来源:SECUNIA
链接:http://secunia.com/advisories/29711
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9202
来源:SECUNIA
链接:http://secunia.com/advisories/29313
来源:SECUNIA
链接:http://secunia.com/advisories/30899
来源:SUNALERT
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
来源:FEDORA
链接:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html
来源:SECUNIA
链接:http://secunia.com/advisories/32222
来源:SECUNIA
链接:http://secunia.com/advisories/32266
来源:CONFIRM
链接:http://tomcat.apache.org/security-4.html
来源:DEBIAN
链接:http://www.debian.org/security/2008/dsa-1447
来源:SECUNIA
链接:http://secunia.com/advisories/27481
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2008/1856/references
来源:REDHAT
链接:http://rhn.redhat.com/errata/RHSA-2008-0630.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2007/3622
来源:CONFIRM
链接:http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm
来源:SECUNIA