CNCVE编号:CNCVE-20000923 CVE编号:CVE-2000-0923 安全级别:中 漏洞中文描述: Aplio PRO中的authenticate.cgi中的目录遍历漏洞导致远程攻击者可以通过在“password”参数中使用“..”攻击来阅读任意文件。 漏洞英文描述: authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter. 漏洞参考: BUGTRAQ:20001006 Fwd: APlio PRO web shell | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0107.html | XF:uclinux-apliophone-bin-execute | URL:http://xforce.iss.net/static/5333.php | BID:1784 | URL:http://www.securityfocus. 系统类型: 其他 漏洞类型:输入有效性检查错误