CNCVE编号:CNCVE-20001100 CVE编号:CAN-2000-1100 安全级别:高 漏洞中文描述: PostACI webmail系统默认在web根目录下安装/includes/global.inc配置文件这允许远程攻击者通过直接的HTTP GET请求来阅读诸如数据库用户名和口令等敏感信息。 漏洞英文描述: The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET reque 漏洞参考: BUGTRAQ:20001130 PostACI Webmail Vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0433.html | BID:2029 | URL:http://www.securityfocus.com/bid/2029 系统类型:其他 漏洞类型:权限有效性检查错误