CNCVE编号:CNCVE-20010842 CVE编号:CAN-2001-0842 安全级别:高 漏洞中文描述: LB5000 LB5000II 1029及其早期版本中的search.cgi程序中的目录遍历漏洞允许远程攻击者通过在“amembernamecookie”cookie中使用“..”序列来覆盖文件和获得权限。 漏洞英文描述: Directory traversal vulnerability in Search.cgi in LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie. 漏洞参考: Reference: BUGTRAQ:20011030 LB5000 Cookie filter vulnerability Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100446455809273&w=2 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误