CNCVE编号:CNCVE-20000922 CVE编号:CVE-2000-0922 安全级别:中 漏洞中文描述: Bytes交互式网络购物的购物车程序2.0版及其早期版本中的shopper.cgi中的目录遍历漏洞导致远程攻击者通过在“newpage”参数中使用“..”攻击来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter. 漏洞参考: BUGTRAQ:20001008 Security Advisory: Bytes Interactive's Web Shopper (shopper.cgi) Directory Traversal Vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0120.html | BID:1776 | URL:http://www.securityfocus.com/bid/1776 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误