CNCVE编号:CNCVE-20010206 CVE编号:CAN-2001-0206 安全级别:高 漏洞中文描述: Soft Lite ServerWorx 3.00中的目录遍历漏洞允许远程攻击者通过把“..”或“…”嵌入一个HTTP GET请求的路径名中来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request. 漏洞参考: Reference: BUGTRAQ:20010207 Vulnerability in Soft Lite ServerWorx Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0137.html Reference: BID:2346 Reference: URL:http://www.securityfocus.com/bid/2346 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误