CNCVE编号:CNCVE-20000811 CVE编号:CVE-2000-0811 安全级别:中 漏洞中文描述: Auction Weaver 1.0 到 1.04版本中存在一个漏洞,该漏洞导致远程攻击者可以通过对用户或 bidfile 表单域的“..”攻击阅读任意文件。 漏洞英文描述: Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields. 漏洞参考: BUGTRAQ:20001016 File deletion and other bugs in Auction Weaver LITE 1.0 - 1.04 | BID:1783 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:权限有效性检查错误