查看: 1695|回复: 0
收起左侧

[求助] pjblog 程序物理路径暴露漏洞

[复制链接]
yxwxqflbyg
发表于 2007-12-23 16:48:52 | 显示全部楼层 |阅读模式
inurl:GuestBookForPJBlog   这个是博客留言插件,百度找到这个肯定是 pjblog。
inurl:trackback.asp              搜索可以找到90%以上为pjblog
    for each x in Request.ServerVariables
      response.write("<b>" & x & "</b>: " & Request.ServerVariables(x) & "<br />")
    next
   
%>
ALL_RAW: Connection: Keep-Alive Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword, */* Accept-Encoding: gzip, deflate Accept-Language: zh-cn Cookie: xiaogunSetting=; ASPSESSIONIDSACSCBRT=OIJNIKFCAMPMAICLEAAGHNCH Host: www.luffyes.com User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
APPL_MD_PATH: /LM/w3svc/281/ROOT
APPL_PHYSICAL_PATH: f:\usr\cn20280\
AUTH_PASSWORD:
AUTH_TYPE:
AUTH_USER:
CERT_COOKIE:
CERT_FLAGS:
CERT_ISSUER:
CERT_KEYSIZE:
CERT_SECRETKEYSIZE:
CERT_SERIALNUMBER:
CERT_SERVER_ISSUER:
CERT_SERVER_SUBJECT:
CERT_SUBJECT:
CONTENT_LENGTH: 0
CONTENT_TYPE:
GATEWAY_INTERFACE: CGI/1.1
HTTPS: off
HTTPS_KEYSIZE:
HTTPS_SECRETKEYSIZE:
HTTPS_SERVER_ISSUER:
HTTPS_SERVER_SUBJECT:
INSTANCE_ID: 281
INSTANCE_META_PATH: /LM/W3SVC/281
LOCAL_ADDR: 218.244.136.31
LOGON_USER:
PATH_INF /life.asp
PATH_TRANSLATED: f:\usr\cn20280\life.asp
QUERY_STRING:
REMOTE_ADDR: 123.56.213.224
REMOTE_HOST: 123.56.213.224
REMOTE_USER:
REQUEST_METHOD: GET
SCRIPT_NAME: /life.asp
SERVER_NAME: www.luffyes.com
SERVER_PORT: 80
SERVER_PORT_SECURE: 0
SERVER_PROTOCOL: HTTP/1.1
SERVER_SOFTWARE: Microsoft-IIS/6.0
URL: /life.asp
HTTP_CONNECTION: Keep-Alive
HTTP_ACCEPT: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword, */*
HTTP_ACCEPT_ENCODING: gzip, deflate
HTTP_ACCEPT_LANGUAGE: zh-cn
HTTP_COOKIE: xiaogunSetting=; ASPSESSIONIDSACSCBRT=OIJNIKFCAMPMAICLEAAGHNCH
HTTP_HOST: www.luffyes.com
HTTP_USER_AGENT: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
物理路径为:APPL_PHYSICAL_PATH: f:\usr\cn20280\life.asp
2、直接删除 life.asp 文件。(如果你本地有备份的话可以使用)
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-4 02:44 , Processed in 0.150722 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表