RSA SecurID WebID Unicode Directory...

- AV AC AU C I A
发布: 2001-10-22
修订: 2025-04-13

RSA SecurID is a commercial product which provides local and remote authentication to restrict unauthorized access to resources on a host. WebID provides web-based authentication. A vulnerability exists in SecurID which could allow an unauthorized user to gain access to a known file residing on the target host. This is achievable if a specially crafted URL composed of double dot "../" directory traversal sequences, with Unicode character representations substituted for "/" and "\" , is submitted to a host. Disclosure of sensitive information may allow for more 'intelligent' attacks.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息