CNCVE编号:CNCVE-20010808 CVE编号:CAN-2001-0808 安全级别:高 漏洞中文描述: GNATS GnatsWeb 2.7到 3.95中的gnatsweb.pl允许远程攻击者通过 help_file参数中的某些字符来执行任意命令。 漏洞英文描述: gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter. 漏洞参考: Reference: BUGTRAQ:20010627 gnats update Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0365.html Reference: CONFIRM:http://sources.redhat.com/gnats/gnatsweb/advisory-jun-26-2001.html Reference: XF:gnatsweb-helpfile-execute-c 系统类型: 其他 漏洞类型:输入有效性检查错误