CNCVE编号:CNCVE-20010562 CVE编号:CAN-2001-0562 安全级别:中 漏洞中文描述: Drummond Miles A1Stats早期到1.6版本中的aldisp.cgi程序允许远程攻击者通过一个指定的包含shell元字符的URL来执行命令。 漏洞英文描述: a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters. 漏洞参考: Reference: BUGTRAQ:20010507 Advisory for A1Stats Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0047.html Reference: BID:2705 Reference: URL:http://www.securityfocus.com/bid/2705 Reference: XF:a1stats-a1admin-dos(6505) Refere 系统类型:其他 漏洞类型:输入有效性检查错误