CNCVE编号:CNCVE-20010730 CVE编号:CAN-2001-0730 安全级别:中 漏洞中文描述: Apache 1.3.20中的split-logfile允许远程攻击者通过一个带有Host:报头中的 “/”(斜杠)的HTTP请求来覆盖以.log扩展符结尾的任意文件。 漏洞英文描述: split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header. 漏洞参考: Reference: CONFIRM:http://www.apacheweek.com/issues/01-09-28#security 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误