CNCVE编号:CNCVE-20010574 CVE编号:CAN-2001-0574 安全级别:中 漏洞中文描述: MP3Mystic 1.04b3早期版本中的目录遍历漏洞允许远程攻击者通过在URL中的“..”来下载任意文件。 漏洞英文描述: Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL. 漏洞参考: Reference: BUGTRAQ:20010507 Advisory for MP3Mystic Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0046.html Reference: CONFIRM:http://mp3mystic.com/mp3mystic/news.phtml Reference: XF:mp3mystic-dot-directory-traversal(6504) Ref 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误