积极预防 及时发现
快速响应 力保恢复
Ultraboard 2000 2.11的默认安装过程允许样式、数据库和备份目录等全局可写,这将允许...
发布时间:2001-03-12 信息来源:管理员

CNCVE编号:CNCVE-20010135 CVE编号:CAN-2001-0135 安全级别:中 漏洞中文描述: Ultraboard 2000 2.11的默认安装过程允许样式、数据库和备份目录等全局可写,这将允许本地用户修改敏感信息和有可能插入或执行CGI程序。 漏洞英文描述: The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs. 漏洞参考: BID:2197 BUGTRAQ:20010112 UltraBoard cgi directory permission problem 系统类型:其他 漏洞类型:权限有效性检查错误