Apache
tcp/443 tcp/80
An attacker can make use of this vulnerability to step out of the root directory and access other parts of the file system.
This might give the attacker the ability to view restricted files, which could provide the attacker with more information required to further compromise the system.
https://www.acunetix.com/websitesecurity/directory-traversal/
Severity: critical
Fingerprint: ac4d53c4832b2491c591c07d6a1c751cd69cc7ad3aeeabb03aeeabb03aeeabb0
Found host file trough Directory traversal: ::1 localhost localhost.localdomain localhost6 localhost6.localdomain6 127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 127.0.0.1 ecs-33808 ecs-33808
Open service 120.46.164.250:80 · 28e587.com
2024-12-12 05:26
HTTP/1.1 500 Internal Server Error Date: Thu, 12 Dec 2024 05:26:07 GMT Server: Apache Product: Z-BlogPHP 1.7.3 X-XSS-Protection: 1; mode=block Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Page title: 我的网站-错误 <!doctype html> <html lang="zh-Hans"> <head> <meta charset="utf-8" /> <meta name="robots" content="noindex,nofollow,noarchive" /> <meta name="generator" content="Z-BlogPHP 1.7.3"/> <meta http-equiv="X-UA-Compatible" content="ie=edge"/> <meta name="renderer" content="webkit" /> <meta name="viewport" content="width=device-width,viewport-fit=cover" /> <title>我的网站-错误</title> <link rel="stylesheet" href="http://28e587.com/zb_system/css/admin.css?173295" type="text/css" media="screen"/> <script src="http://28e587.com/zb_system/script/common.js?173295"></script> </head> <body class="error short"> <div class="bg"> <div id="wrapper"> <div class="logo"><img src="http://28e587.com/zb_system/image/admin/none.gif" title="Z-BlogPHP" alt="Z-BlogPHP"/></div> <div class="login loginw"> <form id="frmLogin" method="post" action="#"> <div class="divHeader lessinfo" style="margin-bottom:10px;"> <b>主题模板的编译文件不存在。</b></div> <div class="content lessinfo"> <div> <p style="font-weight: normal;">可能的错误原因</p> 请复制上方错误信息到搜索引擎以获取关于该错误的说明,或点击<a href="https://cn.bing.com/search?q=%E4%B8%BB%E9%A2%98%E6%A8%A1%E6%9D%BF%E7%9A%84%E7%BC%96%E8%AF%91%E6%96%87%E4%BB%B6%E4%B8%8D%E5%AD%98%E5%9C%A8%E3%80%82" rel="nofollow" target="_blank">「使用必应搜索」。</a><br/><br/> 如果您是访客,这说明网站程序可能出现了一些错误。请您稍后再试,或联系站长。<br/><br/> 如果您是站长,可以<a href="https://docs.zblogcn.com/php/#/books/start-25-faq" rel="nofollow" target="_blank">「点击这里」</a>查看 Z-Blog 官方对于【部分常见错误 】的说明,,以及<a href="https://docs.zblogcn.com/php/#/books/start-25-faq" rel="nofollow" target="_blank">「通用排查指南」</a>。<br/> 如果仍然无法解决,也可以到 <a href="https://bbs.zblogcn.com/" rel="nofollow" target="_blank">Z-Blog 官方论坛</a>,附上当前错误信息与描述寻求帮助。 注:请将"当前错误信息"复制进标题或正文中。<br/> </div> </div> <div class="goback"> <a href="javascript:history.back(-1);">返回</a> <a href="javascript:location.reload();">刷新</a> <a href="http://28e587.com/zb_system/cmd.php?act=login">登录</a> </div> </form> </div> </div> </div> </body> </html><!--35.31 ms , 6 queries , 2065kb memory , 7 errors-->
Open service 120.46.164.250:80 · www.28e587.com
2024-12-12 05:26
HTTP/1.1 500 Internal Server Error Date: Thu, 12 Dec 2024 05:26:07 GMT Server: Apache Product: Z-BlogPHP 1.7.3 X-XSS-Protection: 1; mode=block Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Page title: 我的网站-错误 <!doctype html> <html lang="zh-Hans"> <head> <meta charset="utf-8" /> <meta name="robots" content="noindex,nofollow,noarchive" /> <meta name="generator" content="Z-BlogPHP 1.7.3"/> <meta http-equiv="X-UA-Compatible" content="ie=edge"/> <meta name="renderer" content="webkit" /> <meta name="viewport" content="width=device-width,viewport-fit=cover" /> <title>我的网站-错误</title> <link rel="stylesheet" href="http://www.28e587.com/zb_system/css/admin.css?173295" type="text/css" media="screen"/> <script src="http://www.28e587.com/zb_system/script/common.js?173295"></script> </head> <body class="error short"> <div class="bg"> <div id="wrapper"> <div class="logo"><img src="http://www.28e587.com/zb_system/image/admin/none.gif" title="Z-BlogPHP" alt="Z-BlogPHP"/></div> <div class="login loginw"> <form id="frmLogin" method="post" action="#"> <div class="divHeader lessinfo" style="margin-bottom:10px;"> <b>主题模板的编译文件不存在。</b></div> <div class="content lessinfo"> <div> <p style="font-weight: normal;">可能的错误原因</p> 请复制上方错误信息到搜索引擎以获取关于该错误的说明,或点击<a href="https://cn.bing.com/search?q=%E4%B8%BB%E9%A2%98%E6%A8%A1%E6%9D%BF%E7%9A%84%E7%BC%96%E8%AF%91%E6%96%87%E4%BB%B6%E4%B8%8D%E5%AD%98%E5%9C%A8%E3%80%82" rel="nofollow" target="_blank">「使用必应搜索」。</a><br/><br/> 如果您是访客,这说明网站程序可能出现了一些错误。请您稍后再试,或联系站长。<br/><br/> 如果您是站长,可以<a href="https://docs.zblogcn.com/php/#/books/start-25-faq" rel="nofollow" target="_blank">「点击这里」</a>查看 Z-Blog 官方对于【部分常见错误 】的说明,,以及<a href="https://docs.zblogcn.com/php/#/books/start-25-faq" rel="nofollow" target="_blank">「通用排查指南」</a>。<br/> 如果仍然无法解决,也可以到 <a href="https://bbs.zblogcn.com/" rel="nofollow" target="_blank">Z-Blog 官方论坛</a>,附上当前错误信息与描述寻求帮助。 注:请将"当前错误信息"复制进标题或正文中。<br/> </div> </div> <div class="goback"> <a href="javascript:history.back(-1);">返回</a> <a href="javascript:location.reload();">刷新</a> <a href="http://www.28e587.com/zb_system/cmd.php?act=login">登录</a> </div> </form> </div> </div> </div> </body> </html><!--34.41 ms , 6 queries , 2065kb memory , 7 errors-->
Open service 120.46.164.250:443 · 28e587.com
2024-12-12 05:26
HTTP/1.1 500 Internal Server Error Date: Thu, 12 Dec 2024 05:26:13 GMT Server: Apache Product: Z-BlogPHP 1.7.3 X-XSS-Protection: 1; mode=block Upgrade-Insecure-Requests: 1 Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Page title: 我的网站-错误 <!doctype html> <html lang="zh-Hans"> <head> <meta charset="utf-8" /> <meta name="robots" content="noindex,nofollow,noarchive" /> <meta name="generator" content="Z-BlogPHP 1.7.3"/> <meta http-equiv="X-UA-Compatible" content="ie=edge"/> <meta name="renderer" content="webkit" /> <meta name="viewport" content="width=device-width,viewport-fit=cover" /> <title>我的网站-错误</title> <link rel="stylesheet" href="https://28e587.com/zb_system/css/admin.css?173295" type="text/css" media="screen"/> <script src="https://28e587.com/zb_system/script/common.js?173295"></script> </head> <body class="error short"> <div class="bg"> <div id="wrapper"> <div class="logo"><img src="https://28e587.com/zb_system/image/admin/none.gif" title="Z-BlogPHP" alt="Z-BlogPHP"/></div> <div class="login loginw"> <form id="frmLogin" method="post" action="#"> <div class="divHeader lessinfo" style="margin-bottom:10px;"> <b>主题模板的编译文件不存在。</b></div> <div class="content lessinfo"> <div> <p style="font-weight: normal;">可能的错误原因</p> 请复制上方错误信息到搜索引擎以获取关于该错误的说明,或点击<a href="https://cn.bing.com/search?q=%E4%B8%BB%E9%A2%98%E6%A8%A1%E6%9D%BF%E7%9A%84%E7%BC%96%E8%AF%91%E6%96%87%E4%BB%B6%E4%B8%8D%E5%AD%98%E5%9C%A8%E3%80%82" rel="nofollow" target="_blank">「使用必应搜索」。</a><br/><br/> 如果您是访客,这说明网站程序可能出现了一些错误。请您稍后再试,或联系站长。<br/><br/> 如果您是站长,可以<a href="https://docs.zblogcn.com/php/#/books/start-25-faq" rel="nofollow" target="_blank">「点击这里」</a>查看 Z-Blog 官方对于【部分常见错误 】的说明,,以及<a href="https://docs.zblogcn.com/php/#/books/start-25-faq" rel="nofollow" target="_blank">「通用排查指南」</a>。<br/> 如果仍然无法解决,也可以到 <a href="https://bbs.zblogcn.com/" rel="nofollow" target="_blank">Z-Blog 官方论坛</a>,附上当前错误信息与描述寻求帮助。 注:请将"当前错误信息"复制进标题或正文中。<br/> </div> </div> <div class="goback"> <a href="javascript:history.back(-1);">返回</a> <a href="javascript:location.reload();">刷新</a> <a href="https://28e587.com/zb_system/cmd.php?act=login">登录</a> </div> </form> </div> </div> </div> </body> </html><!--33.74 ms , 6 queries , 2065kb memory , 7 errors-->
Open service 120.46.164.250:443 · www.28e587.com
2024-12-12 05:26
HTTP/1.1 500 Internal Server Error Date: Thu, 12 Dec 2024 05:26:12 GMT Server: Apache Product: Z-BlogPHP 1.7.3 X-XSS-Protection: 1; mode=block Upgrade-Insecure-Requests: 1 Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8 Page title: 我的网站-错误 <!doctype html> <html lang="zh-Hans"> <head> <meta charset="utf-8" /> <meta name="robots" content="noindex,nofollow,noarchive" /> <meta name="generator" content="Z-BlogPHP 1.7.3"/> <meta http-equiv="X-UA-Compatible" content="ie=edge"/> <meta name="renderer" content="webkit" /> <meta name="viewport" content="width=device-width,viewport-fit=cover" /> <title>我的网站-错误</title> <link rel="stylesheet" href="https://www.28e587.com/zb_system/css/admin.css?173295" type="text/css" media="screen"/> <script src="https://www.28e587.com/zb_system/script/common.js?173295"></script> </head> <body class="error short"> <div class="bg"> <div id="wrapper"> <div class="logo"><img src="https://www.28e587.com/zb_system/image/admin/none.gif" title="Z-BlogPHP" alt="Z-BlogPHP"/></div> <div class="login loginw"> <form id="frmLogin" method="post" action="#"> <div class="divHeader lessinfo" style="margin-bottom:10px;"> <b>主题模板的编译文件不存在。</b></div> <div class="content lessinfo"> <div> <p style="font-weight: normal;">可能的错误原因</p> 请复制上方错误信息到搜索引擎以获取关于该错误的说明,或点击<a href="https://cn.bing.com/search?q=%E4%B8%BB%E9%A2%98%E6%A8%A1%E6%9D%BF%E7%9A%84%E7%BC%96%E8%AF%91%E6%96%87%E4%BB%B6%E4%B8%8D%E5%AD%98%E5%9C%A8%E3%80%82" rel="nofollow" target="_blank">「使用必应搜索」。</a><br/><br/> 如果您是访客,这说明网站程序可能出现了一些错误。请您稍后再试,或联系站长。<br/><br/> 如果您是站长,可以<a href="https://docs.zblogcn.com/php/#/books/start-25-faq" rel="nofollow" target="_blank">「点击这里」</a>查看 Z-Blog 官方对于【部分常见错误 】的说明,,以及<a href="https://docs.zblogcn.com/php/#/books/start-25-faq" rel="nofollow" target="_blank">「通用排查指南」</a>。<br/> 如果仍然无法解决,也可以到 <a href="https://bbs.zblogcn.com/" rel="nofollow" target="_blank">Z-Blog 官方论坛</a>,附上当前错误信息与描述寻求帮助。 注:请将"当前错误信息"复制进标题或正文中。<br/> </div> </div> <div class="goback"> <a href="javascript:history.back(-1);">返回</a> <a href="javascript:location.reload();">刷新</a> <a href="https://www.28e587.com/zb_system/cmd.php?act=login">登录</a> </div> </form> </div> </div> </div> </body> </html><!--34.43 ms , 6 queries , 2065kb memory , 7 errors-->