Schmid Watson Management Console目录遍历漏洞


发布日期:2013-01-10
更新日期:2013-01-13

受影响系统:
schmid-telecom Watson Management Console 4.11.2.G
描述:
--------------------------------------------------------------------------------
BUGTRAQ  ID: 57237
 
Watson Management Console是SHDSL路由器 2P 8xEthernet桌面。
 
Watson Management Console存在目录遍历漏洞,此漏洞源于服务器没有正确验证用户提供的http请求,此漏洞可允许攻击者转义Web服务器根目录,并查看其中的可读文件。
 
<*来源:Dhruv Shah
 
  链接:http://www.exploit-db.com/exploits/23995/
 *>

测试方法:
--------------------------------------------------------------------------------

警 告

以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!
# Exploit Title: Watson Management Console Directory Traversal Vulnerability
 # Google Dork: allintitle:Watson Management Console
 # Contacted Vendor : 17/12/2012 as well as 31/12/2012 The Vendor Did
 Not Respond .
 # Date: 1/2/2013
 # Exploit Author: Dhruv Shah
 # Vendor Homepage: http://www.schmid-telecom.com/
 # Software Link: N/A
 # Version: 441A800W0G (4.11.2.G)
 # Platform:Hardware

 Watson Management Console is a ( Watson SHDSL Router 2p 8xEthernet Tabletop )

 It has been found that Watson Management Console is prone to a
 directory traversal vulnerability. The issue is due to the server's
 failure to properly validate user supplied http requests.

 This issue may allow an attacker to escape the web server root
 directory and view any web server readable files. Information acquired
 by exploiting this issue may be used to aid further attacks against a
 vulnerable system.

 http://www.example.com

 in burpsuite proxy or any proxy http request proxy that u use edit the
 Request paramater to

 GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/passwd
 HTTP/1.1

 --
 Regards
 Snypter a.k.a Dhruv Shah
 http://blog.snypter.com
 http://www.youtube.com/snypter
 http://www.facebook.com/dhruvshahs

建议:
--------------------------------------------------------------------------------
厂商补丁:
 
schmid-telecom
 --------------
 目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:
 
http://www.schmid-telecom.com/

相关内容

    暂无相关文章