CNCVE编号:CNCVE-20010418 CVE编号:CAN-2001-0418 安全级别:中 漏洞中文描述: NCM Content Management System 中的content.pl脚本允许远程攻击者通过把SQL字符嵌入id参数来阅读 content数据库中的任意内容。 漏洞英文描述: content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter. 漏洞参考: Reference: BUGTRAQ:20010413 Exploitable NCM.at - Content Management System Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0223.html Reference: BID:2584 Reference: URL:http://www.securityfocus.com/bid/2584 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误