积极预防 及时发现
快速响应 力保恢复
eXtropia bbs_forum.cgi 1.0中的目录遍历漏洞允许远程攻击者通过在“file”...
发布时间:2001-03-12 信息来源:管理员

CNCVE编号:CNCVE-20010123 CVE编号:CVE-2001-0123 安全级别:中 漏洞中文描述: eXtropia bbs_forum.cgi 1.0中的目录遍历漏洞允许远程攻击者通过在“file”参数中使用“..”(跳转到上级目录)攻击来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter. 漏洞参考: BID:2177 BUGTRAQ:20010107 Cgisecurity.com Advisory #3.1 系统类型:其他 漏洞类型:输入有效性检查错误