CVE-2012-4940 PoC — Axigen Free Mail Server ‘View Log Files’组件多个目录遍历漏洞
关联漏洞
标题:Axigen Free Mail Server ‘View Log Files’组件多个目录遍历漏洞 (CVE-2012-4940)Description:Axigen Messaging Axigen Mail Server是罗马尼亚Axigen Messaging公司的一款小型的邮件服务器,它可与SMTP、IMAP和WebMail等服务相结合使用。 Axigen Free邮件服务器中的View Log Files组件中存在多个目录遍历漏洞。通过将..(点点)植入(1)下载操作中的fileName参数传送到source/loggin/page_log_dwn_file.hsp,或(2)编辑操作或(3)删除操作中的fileName参数传送到默认的URI,远程
Description
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in an edit or delete action to the default URI.
文件快照
备注
1. 建议优先通过来源进行访问。
2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →