webfs是一款轻量级HTTP服务程序。 webfs没有正确处理用户提交的主机名请求,远程攻击者可以利用这个漏洞获得系统敏感信息,如路径信息。 当程序使用虚拟主机时,如果远程客户端请求中 指定".."为主机名,可导致返回文档ROOT目录中的目录列表或文件信息。攻击者可以结合其他漏洞对系统进行进一步攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2003-0543 | OpenSSL ASN.1多个解析安全漏洞 | |
| CVE-2003-0544 | OpenSSL ASN.1多个解析安全漏洞 | |
| CVE-2003-0545 | OpenSSL ASN.1多个解析安全漏洞 | |
| CVE-2003-0830 | marbles本地环境变量缓冲区溢出漏洞 | |
| CVE-2003-0833 | WebFS长路径名缓冲区溢出漏洞 | |
| CVE-2003-0835 | MPlayer流ASX头字段解析缓冲区溢出漏洞 |
No comments yet