积极预防 及时发现
快速响应 力保恢复
DCForum 2000 1.0中的dcboard.cgi程序允许远程攻击者通过上载一个Perl程序...
发布时间:2001-07-02 信息来源:管理员

CNCVE编号:CNCVE-20010436 CVE编号:CAN-2001-0436 安全级别:高 漏洞中文描述: DCForum 2000 1.0中的dcboard.cgi程序允许远程攻击者通过上载一个Perl程序到服务器上并在程序的“AZ”参数中使用“..”攻击来执行任意命令。 漏洞英文描述: dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program. 漏洞参考: Reference: BUGTRAQ:20010416 qDefense Advisory: DCForum allows remote read/write/execute Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html Reference: CONFIRM:http://www.dcscripts.com/FAQ/sec_2001_03_31.html Reference: B 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误