Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-9609 PoC — Netsweeper 路径遍历漏洞

Source
Associated Vulnerability
Title:Netsweeper 路径遍历漏洞 (CVE-2014-9609)
Description:Netsweeper是加拿大Netsweeper公司的一套Web内容过滤解决方案。 Netsweeper 3.1.10之前版本、4.0.9之前的4.0.x版本和4.1.2之前的4.1.x版本中的webadmin/reporter/view_server_log.php文件存在路径遍历漏洞。该漏洞源于网络系统或产品未能正确地过滤资源或文件路径中的特殊元素。攻击者可利用该漏洞访问受限目录之外的位置。
Description
A directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action.
File Snapshot

id: CVE-2014-9609 info: name: Netsweeper 4.0.8 - Directory Traversal author: daffainfo severi ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.