CNCVE编号:CNCVE-20000940 CVE编号:CAN-2000-0940 安全级别:低 漏洞中文描述: Metertek pagelog.cgi中的目录遍历漏洞导致远程攻击者可以通过在“name”或“display”参数中使用“..”攻击来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter. 漏洞参考: BUGTRAQ:20001029 Minor bug in Pagelog.cgi | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0422.html | BID:1864 | URL:http://www.securityfocus.com/bid/1864 | XF:pagelog-cgi-dir-traverse | URL:http://xforce.iss.net/static/54 系统类型:其他 漏洞类型:权限有效性检查错误