CNCVE编号:CNCVE-20010330 CVE编号:CVE-2001-0330 安全级别:高 漏洞中文描述: Bugzilla 2.10允许远程攻击者通过对global.pl文件的HTTP请求来访问包括数据库用户名和口令等敏感信息,global.pl文件一般不被执行由网络服务器返回。 漏洞英文描述: Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed. 漏洞参考: ATSTAKE:A043001-1 URL:http://www.atstake.com/research/advisories/2001/a043001-1.txt BID:2671 URL:http://www.securityfocus.com/bid/2671 系统类型: Unix/Linux Win95/98/ME Win2000/NT 其他 漏洞类型:配置错误