022805.txt...

- AV AC AU C I A
发布: 2005-03-01
修订: 2025-04-13

This paper describes several techniques for exposing file contents using the site search functionality. It is assumed that a site contains documents which are not visible/accessible to external users. Such documents are typically future PR items, or future security advisories, uploaded to the website beforehand. However, the site is also searchable via an internal search facility, which does have access to those documents, and as such, they are indexed by it not via web crawling, but rather, via direct access to the files. Therein lies the security breach.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息