CNCVE编号:CNCVE-20010765 CVE编号:CAN-2001-0765 安全级别:中 漏洞中文描述: BisonFTP V4R1 允许本地用户通过上传 .bdl文件来访问自己主目录外的目录,这样能够被链接到其他目录。 漏洞英文描述: BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories. 漏洞参考: Reference: BUGTRAQ:20010702 BisonFTP Server V4R1 *.bdl upload Directory Traversal Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0025.html Reference: CONFIRM:http://www.bisonftp.com/ServRev.htm Reference: BID:2963 Reference: 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:权限有效性检查错误