积极预防 及时发现
快速响应 力保恢复
Entrust GetAccess中的目录遍历漏洞允许远程攻击者在help.gas.bat或Abou...
发布时间:2001-12-06 信息来源:管理员

CNCVE编号:CNCVE-20010853 CVE编号:CAN-2001-0853 安全级别:中 漏洞中文描述: Entrust GetAccess中的目录遍历漏洞允许远程攻击者在help.gas.bat或AboutBx.gas.bat的本地参数中使用“..”命令来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat. 漏洞参考: Reference: BUGTRAQ:20011105 New getAccess Vulnerability Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100498111712723&w=2 Reference: BUGTRAQ:20011105 Entrust Bulletin E01-005: GetAccess Access Service vulnerability Reference: URL:h 系统类型: 其他 漏洞类型:设计错误