CNCVE编号:CNCVE-20010360 CVE编号:CAN-2001-0360 安全级别:中 漏洞中文描述: Ikonboard 2.1.7b及其早期版本中help.cgi程序中的目录遍历漏洞允许远程攻击者通过在“helpon”参数中使用“..”攻击来阅读任意文件和文件夹。 漏洞英文描述: Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitary files via a .. (dot dot) attack in the helpon parameter. 漏洞参考: Reference: BUGTRAQ:20010311 Ikonboard v2.1.7b "show files" vulnerability Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0124.html Reference: BID:2471 Reference: URL:http://www.securityfocus.com/bid/2471 Reference: XF:ikonboa 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误