积极预防 及时发现
快速响应 力保恢复
免费在线计算词典(FOLDOC,Free On-Line Dictionary of Computi...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010461 CVE编号:CAN-2001-0461 安全级别:高 漏洞中文描述: 免费在线计算词典(FOLDOC,Free On-Line Dictionary of Computing)中的template.cgi允许远程攻击者通过在template.cgi文件的参数里的shell元字符来阅读文件和执行命令。 漏洞英文描述: template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi. 漏洞参考: Reference: BUGTRAQ:20010309 Cgisecurity.com advisory #4 The Free On-line Dictionary of Computing Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0109.html Reference: CONFIRM:http://wombat.doc.ic.ac.uk/foldoc/index.html Refer 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误