积极预防 及时发现
快速响应 力保恢复
DCScripts DCForum versions 2000及其早期版本允许远程攻击者通过竖杠符号...
发布时间:2001-08-14 信息来源:管理员

CNCVE编号:CNCVE-20010527 CVE编号:CAN-2001-0527 安全级别:高 漏洞中文描述: DCScripts DCForum versions 2000及其早期版本允许远程攻击者通过竖杠符号(|)换行符插入注册表来获得额外的权限,这会造成对注册数据库额外的登录。 漏洞英文描述: DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database. 漏洞参考: Reference: BUGTRAG:20010515 DCForum Password File Manipukation Vulnerability (qDefense Advisory Number QDAV-5-2000-2) Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0122.html Reference: CONFIRM:http://www.dcscripts.com/dcforum 系统类型:其他 漏洞类型:输入有效性检查错误