积极预防 及时发现
快速响应 力保恢复
Interactive Story 1.3的story.pl中的目录遍历漏洞允许远程攻击者通过对“n...
发布时间:2001-12-06 信息来源:管理员

CNCVE编号:CNCVE-20010804 CVE编号:CAN-2001-0804 安全级别:中 漏洞中文描述: Interactive Story 1.3的story.pl中的目录遍历漏洞允许远程攻击者通过对“next”参数上的“..”攻击来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files via a .. (dot dot) attack on the "next" parameter. 漏洞参考: Reference: BUGTRAQ:20010715 Interactive Story File Disclosure Vulnerability Reference: URL:http://www.securityfocus.com/archive/1/4.3.2.7.2.20010715184257.00b20100@compumodel.com Reference: CONFIRM:http://www.valeriemates.com/story_download.html Re 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误