CNCVE编号:CNCVE-20010043 CVE编号:CVE-2001-0043 安全级别:高 漏洞中文描述: phpGroupWare在0.9.7以前的版本中允许远程攻击者通过在phpgw.inc.php程序的phpgw_info参数中指定一个恶意的include文件来执行任意的PHP命令。 漏洞英文描述: phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program. 漏洞参考: BID:2069 XF:phpgroupware-include-files BUGTRAQ:20001206 (SRADV00006) Remote command execution vulnerabilities in phpGroupWare 系统类型:其他 漏洞类型:权限有效性检查错误