CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

Qbik WinGate Log Service Directory Traversal Vulnerability

2016年9月26日 1082点热度 0人点赞 0条评论

漏洞类别:Web server漏洞等级:

漏洞信息

Note: WinGate Versions 2.0 to 4.1 (beta A) are susceptible to this vulnerability.

By default, the WinGate log service is configured to only allow connections from 127.0.0.1; however, the log service can also be set to allow connections from anywhere. Either way, there is a vulnerability that allows any file to be read through the log service port over an HTTP connection.

Update (October 16, 2000): A variation of this vulnerability exists in recent releases of WinGate. By using escaped characters, one can achieve the same effect.

漏洞危害

If successfully exploited, unauthorized users can read any file through the log service port over an HTTP connection.

解决方案

Upgrade to the latest version of WinGate. WinGate Version 4.1 (Beta C) is not susceptible to this vulnerability. You can download WinGate from Qbik's Web site.

0day

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me