CNCVE编号:CNCVE-20010535 CVE编号:CAN-2001-0535 安全级别:高 漏洞中文描述: ColdFusion Server 4.x中的例程不能正确的限制在本地域内访问,这允许远程攻击者通过哄骗在“Web Publish”示例脚本和“Email”示例脚本中的“HTTP Host”(CGI.Host) 变量来实现上载、阅读或执行文件。 漏洞英文描述: Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variability。 漏洞参考: Reference: ISS:20010807 Remote Vulnerabilities in Macromedia ColdFusion Example Applications Reference: URL:http://xforce.iss.net/alerts/advise92.php Reference: ALLAIRE:MPSB01-08 Reference: URL:http://www.allaire.com/Handlers/index.cfm?ID=21700 系统类型: Win2000/NT 漏洞类型:权限有效性检查错误