积极预防 及时发现
快速响应 力保恢复
PHP 3和4不能正确地清除用户引入的格式字符串,这导致远程攻击者可以通过触发那些不能正确写入错误日...
发布时间:2000-12-19 信息来源:管理员

CNCVE编号:CNCVE-20000967 CVE编号:CVE-2000-0967 安全级别:高 漏洞中文描述: PHP 3和4不能正确地清除用户引入的格式字符串,这导致远程攻击者可以通过触发那些不能正确写入错误日志中的错误信息来执行任意命令。 漏洞英文描述: PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs. 漏洞参考: ATSTAKE:A101200-1 | URL:http://www.atstake.com/research/advisories/2000/a101200-1.txt | MANDRAKE:MDKSA-2000:062 | URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-062.php3?dis=7.1 | DEBIAN:20001014 php3: possible remote exploit | 系统类型:其他 漏洞类型:输入有效性检查错误