积极预防 及时发现
快速响应 力保恢复
在MailFile 1.10中的mailfile.cgi程序允许远程攻击者通过在POST请求中在“f...
发布时间:2000-12-19 信息来源:管理员

CNCVE编号:CNCVE-20000977 CVE编号:CVE-2000-0977 安全级别:低 漏洞中文描述: 在MailFile 1.10中的mailfile.cgi程序允许远程攻击者通过在POST请求中在“filename”参数中指定目标文件的名字来阅读任意文件,这个请求随后通过邮件被送往“email”参数指定的地址中。 漏洞英文描述: mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter. 漏洞参考: BUGTRAQ:20001011 Mail File POST Vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html | BID:1807 | URL:http://www.securityfocus.com/bid/1807 系统类型:其他 漏洞类型:输入有效性检查错误