Extent RBS ISP Directory Traversal...

- AV AC AU C I A
发布: 2000-09-21
修订: 2025-04-13

A remote user is capable of gaining read access to any file residing in the same directory of a host running Extent RBS ISP through directory traversal. Appending '../' to the 'image' variable request on port 8002 will enable a user to read any available file includeing credit card details, username, password etc. For example: http://target:8002/Newuser?Image=../../database/rbsserv.mdb

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息