CNCVE编号:CNCVE-20010839 CVE编号:CAN-2001-0839 安全级别:高 漏洞中文描述: iBill口令管理系统中的ibillpm.pl是基于客户的MASTER_ACCOUNT生成弱口令,这允许远程攻击者通过强制口令猜测来修改 .htpasswd file中的帐户信息。 漏洞英文描述: ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing. 漏洞参考: Reference: BUGTRAQ:20011025 Weak authentication in iBill's Password Management CGI Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100404371423927&w=2 系统类型:其他 漏洞类型:输入有效性检查错误