Netwin Netauth Directory Traversal...

- AV AC AU C I A
发布: 2000-08-17
修订: 2025-04-13

A remote user is capable of gaining read access to any known file residing on a host running Netwin Netauth through directory traversal. Appending a series of '../' and the desired file name to the 'page' variable at the end of a request to netauth.cgi will allow a remote user to walk the entire directory tree above the Netauth directory. For example: http://target/cgi-bin/netauth.cgi?cmd=show&page=../../directory will display the contents of the specified directory.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息