CNCVE编号:CNCVE-20010805 CVE编号:CAN-2001-0805 安全级别:中 漏洞中文描述: Tarantella 企业版3.00 and 3.01中的ttawebtop.cgi程序中的目录遍历漏洞允许远程攻击者通过在“pg”参数中使用“..”序列来阅读任意文件。 漏洞英文描述: Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the pg parameter. 漏洞参考: Reference: BUGTRAQ:20010618 SCO Tarantella Remote file read via ttawebtop.cgi Reference: URL:http://www.securityfocus.com/archive/1/3B2E37D0.81D9ED9D@snosoft.com Reference: BUGTRAQ:20010619 Re: SCO Tarantella Remote file read via ttawebtop.cgi Re 系统类型: Unix/Linux Win95/98/ME Win2000/NT Apple其他 漏洞类型:输入有效性检查错误