·¢²¼ÈÕÆÚ£º2008-08-15
¸üÐÂÈÕÆÚ£º2008-08-20
ÊÜÓ°Ïìϵͳ£º
MicroWorld MailScan for Mail Servers 5.6.a espatch1
ÃèÊö£º
BUGTRAQ ID:
30700CVE(CAN) ID:
CVE-2008-3726,
CVE-2008-3727,
CVE-2008-3728,
CVE-2008-3729MailScanÊÇÏȽøµÄÓʼþ·þÎñÆ÷ʵʱɱ¶¾ºÍ·´À¬»øÓʼþ½â¾ö·½°¸¡£
MailScanÌṩÁË»ùÓÚWebµÄ¹ÜÀí¹¦ÄÜ£¬¹ÜÀí¿ØÖÆÌ¨£¨Server.exe£©ÊÇÒÔLocalSystemȨÏÞÔËÐÐÔÚTCP 10443¶Ë¿ÚÉϵÄHTTP·þÎñ¡£¸Ã·þÎñ´æÔÚ¶à¸öÊäÈëÑéÖ¤´íÎó£¬ÔÊÐí¶ñÒâ¹¥»÷Õßй¶Ãô¸ÐÐÅÏ¢¡¢Ö´ÐпçÕ¾½Å±¾»òÈÆ¹ýijЩ°²È«ÏÞÖÆ¡£
1) Ô¶³Ì¹¥»÷Õß¿ÉÒÔÏòWeb¹ÜÀí½Ó¿Ú·¢ËÍÌØÖÆÇëÇóÖ´ÐÐĿ¼±éÀú¹¥»÷£¬ÏÂÔØÈÎÒâÎļþ¡£
2) Web¹ÜÀí½Ó¿ÚûÓÐÕýÈ·µØÏÞÖÆ¶ÔÄ³Ð©Ò³ÃæµÄ·ÃÎÊ£¬¹¥»÷Õß¿ÉÒÔÈÆ¹ýÈÏÖ¤Ö±½Ó·ÃÎÊÊܱ£»¤µÄÒ³Ãæ¡£
3) ÔÚ³öÏÖ´íÎóµÄÇé¿öÏ£¬Ã»ÓÐÕýÈ·µØ¹ýÂ˶ÔWeb¹ÜÀí½Ó¿ÚµÄURLÊäÈë±ã·µ»Ø¸øÁËÓû§£¬Õâ¿ÉÄÜÔÚÓû§ä¯ÀÀÆ÷»á»°ÖÐÖ´ÐÐÈÎÒâHTMLºÍ½Å±¾´úÂë¡£³É¹¦¹¥»÷ÒªÇóÓû§µÄä¯ÀÀÆ÷ûÓÐURL±àÂëÇëÇó£¬ÈçInternet Explorer¡£
<*À´Ô´£ºOliver Karow £¨
Oliver.karow@gmx.de£©
Á´½Ó£º
http://secunia.com/advisories/31534/ http://marc.info/?l=bugtraq&m=121881329424635&w=2*>
²âÊÔ·½·¨£º
¾¯ ¸æ
ÒÔϳÌÐò(·½·¨)¿ÉÄÜ´øÓй¥»÷ÐÔ£¬½ö¹©°²È«Ñо¿Óë½Ìѧ֮Óá£Ê¹ÓÃÕß·çÏÕ×Ô¸º£¡
echo -e "GET /../../../../boot.ini HTTP/1.0\r\n\r\n" | nc <server> <port>
http://ip:10443/<script>alert("No_Problem_its_just_an_admin_interface")</script>http://ip:10443/LOG/W072808.LOGhttp://ip:10443/LOG/Weblog.LOG½¨Ò飺
³§É̲¹¶¡£º
MicroWorld
----------
Ŀǰ³§ÉÌ»¹Ã»ÓÐÌṩ²¹¶¡»òÕßÉý¼¶³ÌÐò£¬ÎÒÃǽ¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§É̵ÄÖ÷Ò³ÒÔ»ñÈ¡×îа汾£º
http://www.mwti.net/index.asp