CNCVE编号:CNCVE-20000902 CVE编号:CAN-2000-0902 安全级别:中 漏洞中文描述: PhotoAlbum 0.9.9 以前版本中的getalbum.php允许远程攻击者通过“..”攻击阅读任意文件。 漏洞英文描述: getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. 漏洞参考: BUGTRAQ:20000907 Re: PhotoAlbum 0.9.9 explorer.php Vulnerability | URL:http://www.securityfocus.com/archive/1/80858 | XF:phpphotoalbum-getalbum-directory-traversal | URL:http://xforce.iss.net/static/5209.php 系统类型: Win2000/NT 漏洞类型:权限有效性检查错误