当前位置:首页 >> 网络通讯 >> 网络安全 >> 内容

SpecView = 2.5 build 853目录遍历

时间:2013/4/19 12:09:00 作者:平凡之路 来源:xuhantao.com 浏览:

Luigi Auriemma
程序:  SpecView
影响版本   <= 2.5 build 853
测试平台:    Windows
漏洞  web server directory traversal
作者  Luigi Auriemma
             
1)概述
2) Bug
3) The Code
4)修复
 
===============
1)介绍说明
===============
 
 
SpecView is an easy to use SCADA software.
 

 
======
2) Bug
======
 
 
The software has an option (disabled by default) that allows to run a
web server for providing an updated screenshot of the program.
This built-in web server is affected by a classical directory
traversal attack through the usage of more than two dots.
 

===========
3) The Code
===========
 
 
/.../.../.../.../.../.../boot.ini
/...\...\...\...\...\...\boot.ini
 
======
4) 修复
======
 
 
No fix. ,www.xuhantao.com,涛涛电脑知识

相关文章
  • 没有相关文章
  • 徐汉涛(www.xuhantao.com) © 2024 版权所有 All Rights Reserved.
  • 部分内容来自网络,如有侵权请联系站长尽快处理 站长QQ:965898558(广告及站内业务受理) 网站备案号:蒙ICP备15000590号-1