积极预防 及时发现
快速响应 力保恢复
ROADS search.pl程序允许远程攻击者通过把文件名列入form参数以及以空字节结束文件名来...
发布时间:2001-06-02 信息来源:管理员

CNCVE编号:CNCVE-20010215 CVE编号:CVE-2001-0215 安全级别:中 漏洞中文描述: ROADS search.pl程序允许远程攻击者通过把文件名列入form参数以及以空字节结束文件名来阅读任意文件。 漏洞英文描述: ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte. 漏洞参考: Reference: BUGTRAQ:20010212 ROADS search system "show files" Vulnerability with "null bite" bug Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0213.html Reference: BID:2371 Reference: URL:http://www.securityfocus.com/bid/23 系统类型:其他 漏洞类型:输入有效性检查错误