CNCVE编号:CNCVE-20000911 CVE编号:CVE-2000-0911 安全级别:中 漏洞中文描述: IMP2.2及其早期版本中存在一个漏洞,该漏洞可导致攻击者通过修改隐藏在表单变量中的附件名(attachment_name)来阅读和删除任意文件,这种修改可以引发IMP把这个文件作为附件发送给攻击者。 漏洞英文描述: IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment. 漏洞参考: BUGTRAQ:20000912 (SRADV00003) Arbitrary file disclosure through IMP | URL:http://www.securityfocus.com/archive/1/82088 | BID:1679 | URL:http://www.securityfocus.com/bid/1679 | XF:imp-attach-file | URL:http://xforce.iss.net/static/522 系统类型:其他 漏洞类型:输入有效性检查错误