积极预防 及时发现
快速响应 力保恢复
SmartWin CyberOffice Shopping Cart 2 (aka CyberSho...
发布时间:2000-12-19 信息来源:管理员

CNCVE编号:CNCVE-20000925 CVE编号:CVE-2000-0925 安全级别:中 漏洞中文描述: SmartWin CyberOffice Shopping Cart 2 (aka CyberShop)的默认安装程序把 _private目录的权限设为全局可读,这使得远程攻击者可以获得敏感信息。 漏洞英文描述: The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information. 漏洞参考: BUGTRAQ:20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97050819812055&w=2 | WIN2KSEC:20001002 DST2K0035: Credit card (customer) details exposed within 系统类型: Win2000/NT 漏洞类型:设计错误