积极预防 及时发现
快速响应 力保恢复
Muscat Empower CGI程序允许远程攻击者通过在DB参数中的非法请求来获得服务器的绝对路...
发布时间:2001-06-02 信息来源:管理员

CNCVE编号:CNCVE-20010224 CVE编号:CAN-2001-0224 安全级别:高 漏洞中文描述: Muscat Empower CGI程序允许远程攻击者通过在DB参数中的非法请求来获得服务器的绝对路径名。 漏洞英文描述: Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter. 漏洞参考: Reference: BUGTRAQ:20010212 Vulnerability in Muscat Empower wich can print path to DB-dir. Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0216.html Reference: BID:2374 Reference: URL:http://www.securityfocus.com/bid/2374 系统类型:其他 漏洞类型:输入有效性检查错误