CNCVE编号:CNCVE-20010214 CVE编号:CAN-2001-0214 安全级别:中 漏洞中文描述: Way-board CGI 程序允许远程攻击者以文件名做为db参数并使用空字节(NULL)结束文件名的方式来阅读任意文件。 漏洞英文描述: Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte. 漏洞参考: Reference: BUGTRAQ:20010212 Way board: "show files" Vulnerability with null bite bug Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0212.html Reference: BID:2370 Reference: URL:http://www.securityfocus.com/bid/2370 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:权限有效性检查错误