CNCVE编号:CNCVE-20010591 CVE编号:CAN-2001-0591 安全级别:高 漏洞中文描述: Oracle JSP 1.0.x到1.1.1 以及 Oracle 8.1.7 iAS Release 1.0.2中的目录遍历漏洞允许远程攻击者通过“..”攻击来阅读或执行任意 .jsp文件。 漏洞英文描述: Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack. 漏洞参考: Reference: WIN2KSEC:20010122 Oracle JSP/SQLJS handlers allow viewing files and executing JSP outside the web root Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2001-q1/0028.html Reference: BUGTRAQ:20010212 Patch for Potentia 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误