积极预防 及时发现
快速响应 力保恢复
IncrediMail 1400185及其早期版本存在目录遍历漏洞允许本地用户通过附加“..”序列到...
发布时间:2001-09-20 信息来源:管理员

CNCVE编号:CNCVE-20010642 CVE编号:CAN-2001-0642 安全级别:高 漏洞中文描述: IncrediMail 1400185及其早期版本存在目录遍历漏洞允许本地用户通过附加“..”序列到content.ini文件中列出的文件名,从而在本地硬盘上覆盖文件。 漏洞英文描述: Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file. 漏洞参考: Reference: BUGTRAQ:20010511 Incredimail allows automatic over writing offiles on your hard disk Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0078.html Reference: XF:incredimail-dot-overwrite-files(6529) 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误