积极预防 及时发现
快速响应 力保恢复
MySQL 3.23.36早期版本中的目录遍历漏洞 允许本地用户通过创立一个其名以“..”开头的数据...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010407 CVE编号:CAN-2001-0407 安全级别:中 漏洞中文描述: MySQL 3.23.36早期版本中的目录遍历漏洞 允许本地用户通过创立一个其名以“..”开头的数据库来修改任意文件和获得权限。 漏洞英文描述: Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot). 漏洞参考: Reference: BUGTRAQ:20010318 potential vulnerability of mysqld running with root privileges (can be used as good DoS or r00t expoloit) Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0237.html Reference: BUGTRAQ:20010327 MySQL 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误