积极预防 及时发现
快速响应 力保恢复
CGIForum 1.0的cgiforum.pl脚本中的目录遍历漏洞允许远程攻击者通过在“these...
发布时间:2001-01-09 信息来源:管理员

CNCVE编号:CNCVE-20001171 CVE编号:CVE-2000-1171 安全级别:低 漏洞中文描述: CGIForum 1.0的cgiforum.pl脚本中的目录遍历漏洞允许远程攻击者通过在“thesection”参数中使用“..”攻击来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "thesection" parameter. 漏洞参考: BUGTRAQ:20001120 CGIForum 1.0 Vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0263.html | BID:1963 | URL:http://www.securityfocus.com/bid/1963 系统类型:其他 漏洞类型:输入有效性检查错误