积极预防 及时发现
快速响应 力保恢复
Auction Weaver 1.0 到 1.04版本不能正确地确认表单域的名称,这导致远程攻击者可...
发布时间:2000-12-19 信息来源:管理员

CNCVE编号:CNCVE-20000810 CVE编号:CVE-2000-0810 安全级别:中 漏洞中文描述: Auction Weaver 1.0 到 1.04版本不能正确地确认表单域的名称,这导致远程攻击者可以通过“..”攻击删除任意文件和目录。 漏洞英文描述: Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack. 漏洞参考: BUGTRAQ:20001016 File deletion and other bugs in Auction Weaver LITE 1.0 - 1.04 | BID:1782 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:权限有效性检查错误