积极预防 及时发现
快速响应 力保恢复
News Desk 1.2中的newsdesk.cgi程序中的目录遍历漏洞允许远程攻击者通过在“t”...
发布时间:2001-03-26 信息来源:管理员

CNCVE编号:CNCVE-20010231 CVE编号:CAN-2001-0231 安全级别:中 漏洞中文描述: News Desk 1.2中的newsdesk.cgi程序中的目录遍历漏洞允许远程攻击者通过在“t”参数中使用“..”攻击来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter. 漏洞参考: BID:2172 XF:newsdesk-cgi-read-files BUGTRAQ:20010103 News Desk 1.2 CGI Vulnerbility 系统类型:其他 漏洞类型:权限有效性检查错误