CNCVE编号:CNCVE-20010821 CVE编号:CAN-2001-0821 安全级别:中 漏洞中文描述: DCShop 1.002 beta的缺省配置把敏感文件存在cgi-bin 目录中,这允许远程攻击者通过一个对orders.txt或auth_user_file.txt的HTTP GET请求来阅读敏感信息。 漏洞英文描述: The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt. 漏洞参考: Reference: BUGTRAQ:20010618 DCShop vulnerability Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0233.html Reference: CONFIRM:http://www.dcscripts.com/dcforum/dcshop/44.html Reference: BID:2889 Reference: URL:http://www.securit 系统类型: 其他 漏洞类型:其他