CNCVE编号:CNCVE-20001166 CVE编号:CAN-2000-1166 安全级别:中 漏洞中文描述: 当“vhosts”变量没有配置到站点上时,Twig webmail system 不能正确地设置它,这允许远程攻击者通过把一个备用的vhosts作为变量列入index.php3程序中来嵌入任意PHP(PHP3)代码。 漏洞英文描述: Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program. 漏洞参考: BUGTRAQ:20001124 Security problems with TWIG webmail system | URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0351.html | BID:1998 | URL:http://www.securityfocus.com/bid/1998 系统类型:其他 漏洞类型:输入有效性检查错误