1
0
mirror of https://github.com/nmap/nmap.git synced 2025-12-24 08:29:04 +00:00
Files
nmap/scripts
paulino c43e0bb970 Added http-litespeed-sourcecode-download:
http-litespeed-sourcecode-download.nse exploits a null-byte poisoning vulnerability in Litespeed Web Servers 4.0.x before 4.0.15 to retrieve the target script's source code by sending a HTTP request with a null byte followed by a .txt file extension (CVE-2010-2333).

If the server is not vulnerable it returns an error 400. If index.php is not found, you may try /phpinfo.php which is also shipped with LiteSpeed Web Server. The attack payload looks like this:
* <code>/index.php\00.txt</code>

References:
* http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2333
* http://www.exploit-db.com/exploits/13850/
2011-07-24 20:13:42 +00:00
..
2011-01-28 17:54:49 +00:00
2010-08-16 18:59:30 +00:00
2011-07-06 21:58:16 +00:00
2010-07-19 16:29:48 +00:00
2011-07-21 05:12:33 +00:00
2011-06-20 21:09:42 +00:00
2010-08-16 18:59:30 +00:00
2010-08-16 18:59:30 +00:00
2011-06-27 20:40:19 +00:00
2010-07-19 16:29:48 +00:00
2010-08-16 18:59:30 +00:00
2010-08-16 18:59:30 +00:00
2011-06-03 09:24:51 +00:00
2011-01-21 08:28:38 +00:00
2011-04-22 22:21:43 +00:00
2010-08-16 18:59:30 +00:00
2011-01-21 08:28:38 +00:00
2010-08-16 18:59:30 +00:00
2011-07-18 16:29:38 +00:00
2010-08-16 18:59:30 +00:00
2011-06-30 09:11:57 +00:00
2010-08-16 18:59:30 +00:00
2010-08-16 18:59:30 +00:00