VMware Studio虚拟应用设备WEB接口文件上传目录遍历漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Bugraq ID: 36199 CVE ID:CVE-2009-2968 VMware Studio是一款用于开发,配置,定制虚拟应用程序和应用设备的解决方案。 VMware Studio支持的web接口组件不正确过滤用户输入,远程攻击者可以利用漏洞上传文件到VMware Studio虚拟应用设备上的任意目录中。 不过此漏洞不影响由 Studio 2.0 beta建立的虚拟机。 VMWare Studio 2.0 beta 用户可联系供应商获得相应产品的补丁或升级程序: VMware Studio 2.0 build 1017-185256 ----------------------------------- http://www.vmware.com/support/developer/studio/ Release notes: http://www.vmware.com/support/developer/studio/studio20/release_notes.ht ml VMware Studio appliance in ZIP (md5sum:58cb40704d12f4ec329b887ae729aba9) (sha1sum:2931a6a4de7e77016d08c6539cab93a6304ab452) VMware Studio appliance in OVA Deployment URL: http://download3.vmware.com/software/studio/studio20/VMware_Studio-2.0.0 .1017-185256_OVF10.ova (md5sum:0b0edb02865ae935bcffcccbf346adc2) (sha1sum:f126339ab0de5b684e60ab7dfd50ddb15f2391cc) VMware Studio appliance in OVF 1.0 Deployment URL: http://download3.vmware.com/software/studio/studio20/VMware_Studio-2.0.0 .1017-185256_OVF10.ovf...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息