CNCVE编号:CNCVE-20010475 CVE编号:CVE-2001-0475 安全级别:高 漏洞中文描述: Jelsoft vBulletin中的index.php不能正确地初始化用于存储模板信息的PHP变量,这允许远程攻击者通过在templatecache参数中的特殊字符来执行任意的PHP代码。 漏洞英文描述: index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter. 漏洞参考: Reference: BUGTRAQ:20010315 vBulletin allows arbitrary code execution Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0180.html Reference: BID:2474 Reference: URL:http://www.securityfocus.com/bid/2474 Reference: CONFIRM:http: 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误