积极预防 及时发现
快速响应 力保恢复
phpMyAdmin 2.2.0 及其早期版本中的目录遍历漏洞允许远程攻击者通过一个传到sql.ph...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010478 CVE编号:CAN-2001-0478 安全级别:高 漏洞中文描述: phpMyAdmin 2.2.0 及其早期版本中的目录遍历漏洞允许远程攻击者通过一个传到sql.php脚本的参数中的“..”来执行任意代码。 漏洞英文描述: Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. 漏洞参考: BUGTRAQ:20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1 URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html BID:2642 URL:http://www.securityfocus.com/bid/2642 系统类型:其他 漏洞类型:输入有效性检查错误