CNCVE编号:CNCVE-20010633 CVE编号:CAN-2001-0633 安全级别:中 漏洞中文描述: 多种UNIX上的SUN Chili!Soft ASP的目录移动漏洞允许远程攻击者通过在例程代码“codebrws.asp”中添加“..”攻击来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'. 漏洞参考: Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html Reference: BUGTRAQ:20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html 系统类型:其他 漏洞类型:输入有效性检查错误