CNCVE编号:CNCVE-20010320 CVE编号:CAN-2001-0320 安全级别:高 漏洞中文描述: PHP-Nuke 4.4 中的bb_smilies.php 和 bbcode_ref.php允许远程攻击者通过把一个空字符和“..”序列嵌入一个畸形用户名变量来阅读任意文件和获得PHP管理员权限。 漏洞英文描述: bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument. 漏洞参考: Reference: BUGTRAQ:20010223 Yet another hole in PHP-Nuke Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0425.html 系统类型:其他 漏洞类型:输入有效性检查错误