Apache Tomcat 6.0.18 UTF8 Directory Traversal Vulnerability
Description As Apache Security Team, this problem occurs because of JAVA side. If your context.xml or server.xml allows ‘allowLinking’and ‘URIencoding’ as ‘UTF-8′, an attacker can obtain your important system files.(e.g. /etc/passwd)
Exploit If your webroot directory has three depth(e.g /usr/local/wwwroot), An attacker can access arbitrary files as below. (Proof-of-concept) http://www.target.com/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/foo/bar
Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability.
Anche se questo mi sembra un tantinello più pericoloso IMHO!
| Print article | This entry was posted by Andrea L. on 13 August 2008 at 18:10, and is filed under exploit, sicurezza, vulnerabilità. Follow any responses to this post through RSS 2.0. You can leave a response or trackback from your own site. |

