积极预防 及时发现
快速响应 力保恢复
PHProjekt 2.1 及其早期版本中的目录遍历漏洞允许远程攻击者通过对文件模块的“..”攻击来...
发布时间:2001-09-20 信息来源:管理员

CNCVE编号:CNCVE-20010648 CVE编号:CAN-2001-0648 安全级别:高 漏洞中文描述: PHProjekt 2.1 及其早期版本中的目录遍历漏洞允许远程攻击者通过对文件模块的“..”攻击来进行未授权动作。 漏洞英文描述: Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module. 漏洞参考: Reference: BUGTRAQ:20010508 security hole in os groupware suite PHProjekt Reference: URL:http://www.securityfocus.com/archive/1/184215 Reference: BID:2702 Reference: URL:http://www.securityfocus.com/bid/2702 Reference: XF:phprojekt-dot-directory-tra 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误