메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16595

관리자 2018.01.25 04:00 조회 수 : 205

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.export_005fdownload_jsp servlet, which listens on TCP port 8081 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of Administrator. Was ZDI-CAN-5118.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16595
번호 제목 글쓴이 날짜 조회 수
437 CVE-2018-0849 관리자 2018.01.25 192
436 CVE-2017-13681 관리자 2017.11.09 192
435 CVE-2016-6995 관리자 2016.10.14 192
434 CVE-2016-3206 관리자 2016.06.17 192
433 CVE-2017-17406 관리자 2018.01.25 191
432 CVE-2017-16599 관리자 2018.01.25 191
431 CVE-2017-14117 관리자 2017.09.04 191
430 CVE-2017-0016 관리자 2017.03.18 191
429 CVE-2018-1000010 관리자 2018.01.25 190
428 CVE-2017-18046 관리자 2018.01.25 190
427 CVE-2017-12098 관리자 2018.01.25 190
426 CVE-2017-14114 관리자 2017.09.04 190
425 CVE-2017-13142 (imagemagick) 관리자 2017.08.27 190
424 CVE-2017-0132 관리자 2017.03.18 190
423 CVE-2017-16607 관리자 2018.01.25 189
위로