CNCVE编号:CNCVE-20000900 CVE编号:CVE-2000-0900 安全级别:中 漏洞中文描述: thttpd 2.19 及更早版本的ssi CGI程序中的目录遍历漏洞可导致远程攻击者通过"%2e%2e" 字符串( “ ..”攻击的一个变种)阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack. 漏洞参考: BUGTRAQ:20001002 thttpd ssi: retrieval of arbitrary world-readable files | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0025.html | XF:acme-thttpd-ssi | URL:http://xforce.iss.net/static/5313.php | BID:1737 | URL:http://ww 系统类型:其他 漏洞类型:输入有效性检查错误