Alaya Webdav Server 1.0.1 ·¢²¼£¬¸Ã°æ±¾Ôö¼ÓÁË·´ XSS ÌØÐÔ£¬Ôö¼ÓÁË HTTP ÈÏÖ¤µÄ×¢Ïú·½·¨ÒÔ¼°Ò»Ð©³£¹æµÄ bug ÐÞ¸´¡£
Alaya ÊÇÒ»¸öÌṩ WebDAV Ö§³ÖµÄ Web ·þÎñÆ÷£¬Ö§³Ö HTTPS ºÍ HTTP£¬Ö§³Öͨ¹ý PAM¡¢/etc/shadow¡¢/etc/passwd ½øÐÐÈÏÖ¤£¬Í¬Ê±Ò²¿ÉÒÔʹÓÃ×Ô¼º¶¨ÒåµÄÎļþ½øÐÐÈÏÖ¤¡£
À´×Ô:¿ªÔ´ÖйúÉçÇø

