漏洞类别:Web Application
漏洞等级:
漏洞信息
Path traversal vulnerability potentially allows an attacker to access restricted files on a web server, outside of the web server root directory, due to improper access control on the web server's resources.
漏洞危害
This vulnerability could allow attackers to expose sensitive files on the web server outside of the web server root directory. An attacker could manipulate a URL in a such way that the web site will execute or reveal the contents of sensitive files that exist on a web server.
This can divulge source code, database configurations, and other sensitive information inside or outside the Web document root, which may be used to launch further attacks against a vulnerable system.
解决方案
Ensure you are running the latest version of the web server software and all patches have been applied.
The web server root directory should not be set to a directory that may contain sensitive files or that remote users shouldn't be able to access.
0daybank
文章评论