SeaNox Devwex目录遍历漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1106774 漏洞类型 路径遍历
发布时间 2002-06-08 更新时间 2005-05-02
CVE编号 CVE-2002-0946 CNNVD-ID CNNVD-200210-209
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21530
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200210-209
|漏洞详情
SeaNoxDevwex1.2002.0601之前版本存在目录遍历漏洞。远程攻击者借助HTTP请求中的..\(点点)序列读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/4978/info

The Seanox DevWex Windows binary version is prone to an issue which may cause arbitrary web-readable files to be disclosed to remote attackers. This problem occurs because DevWex does not sufficiently filter '..\' sequences from web requests. 

GET /..\..\..\..\anyfile
|参考资料

来源:BID
名称:4978
链接:http://www.securityfocus.com/bid/4978
来源:XF
名称:devwex-dotdot-directory-traversal(9299)
链接:http://www.iss.net/security_center/static/9299.php
来源:www.seanox.de
链接:http://www.seanox.de/projects.devwex.php
来源:OSVDB
名称:5048
链接:http://www.osvdb.org/5048
来源:BUGTRAQ
名称:20020608SeaNoxDevwex-DenialofServiceandDirectorytraversal
链接:http://archives.neohapsis.com/archives/bugtraq/2002-06/0056.html