CNCVE编号:CNCVE-20010276 CVE编号:CAN-2001-0276 安全级别:中 漏洞中文描述: BadBlue 1.02.07 Personal Edition 的ext.dll允许远程攻击者不使用任何参数而直接调用ext.dll,通过调用ext.dll,服务器会回送一个包含路径的错误信息,由此确定服务器的物理路径。 漏洞英文描述: ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path. 漏洞参考: |BUGTRAQ:20010217 BadBlue Web Server Ext.dll Vulnerabilities | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98263019502565&w=2 | BID:2390 | URL:http://www.securityfocus.com/bid/2390 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:异常处理错误