积极预防 及时发现
快速响应 力保恢复
EZshopper 3.0 and 2.0中的loadpage.cgi CGI程序允许远程攻击者通过...
发布时间:2001-01-09 信息来源:管理员

CNCVE编号:CNCVE-20001092 CVE编号:CAN-2000-1092 安全级别:低 漏洞中文描述: EZshopper 3.0 and 2.0中的loadpage.cgi CGI程序允许远程攻击者通过在“file”参数中的目标文件名前插入一个“/”符号来实现在Ezshopper数据中列出和阅读文件。 漏洞英文描述: loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter. 漏洞参考: 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误