KeyFocus (KF) web server目录遍历漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1106836 漏洞类型 未知
发布时间 2002-07-08 更新时间 2005-05-02
CVE编号 CVE-2002-1031 CNNVD-ID CNNVD-200210-110
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21597
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200210-110
|漏洞详情
KeyFocus(KF)webserver1.0.2存在漏洞。远程攻击者可以借助包含%00(空)字符的HTTP请求列出目录并读取受限文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/5177/info

It has been reported that version 1.0.2 of KF Web Server discloses the contents of directories when a certain character is present in the URL.

If a remote attacker appends the "%00" character, it will cause the web server to display the contents of the current directory.

http://server_name/subdir/%00
http://server_name/%00
|参考资料

来源:BID
名称:5177
链接:http://www.securityfocus.com/bid/5177
来源:XF
名称:kfwebserver-null-view-dir(9500)
链接:http://www.iss.net/security_center/static/9500.php
来源:www.keyfocus.net
链接:http://www.keyfocus.net/kfws/support/
来源:BUGTRAQ
名称:20020707KFWebServerversion1.0.2showsfileanddirectorycontent
链接:http://online.securityfocus.com/archive/1/281102
来源:VULNWATCH
名称:20020707[VulnWatch]KFWebServerversion1.0.2showsfileanddirectorycontent
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0007.html