CNCVE编号:CNCVE-20000941 CVE编号:CVE-2000-0941 安全级别:高 漏洞中文描述: Kootenay Web KW Whois 1.0 CGI 程序中存在一个漏洞,该漏洞可导致远程攻击者通过在“whois”参数中的shell元字符执行任意命令。 漏洞英文描述: Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter. 漏洞参考: BUGTRAQ:20001029 Remote command execution via KW Whois 1.0 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html | BUGTRAQ:20001029 Re: Remote command execution via KW Whois 1.0 (addition) | URL:http://archives.neohapsis.com/a 系统类型:其他 漏洞类型:输入有效性检查错误