积极预防 及时发现
快速响应 力保恢复
Phusion Webserver是一个商业的HTTP服务器,它运行于Microsoft Windo...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020047 CVE编号: 安全级别:高 漏洞中文描述: Phusion Webserver是一个商业的HTTP服务器,它运行于Microsoft Windows平台。Phusion Webserver存在目录遍历漏洞。使用连续几个"…/"的HTTP请求可以突破wwwroot的限制。一个恶意用户可以浏览目标主机上web用户可读的所有文件,这样会泄漏目标主机上的敏感信息。 漏洞英文描述: Phusion Webserver is a commercial HTTP server that runs on Microsoft Windows 9x/NT/2000 operating systems. Phusion Webserver is prone to directory traversal attacks. It is possible to break out of wwwroot using triple-dot-slash (…/) sequences containing HTTP-encoded variations of "/" and "\". As a result, a malicious web user may browse web-readable files on the host running the vulnerable software. This vulnerability may potentially result in the disclosure of sensitive information contained in web-readable files on the host. It should be noted that webservers normally run with SYSTEM privileges on Microsoft Windows operating systems. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0180.html http://www.bbshareware.com/phusion/ 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误