CNCVE编号:CNCVE-20020071 CVE编号: 安全级别:中 漏洞中文描述: PHP是服务器端脚本语言,实际用来嵌入到HTML文件,使用在多种操作系统下。 PHP的move_uploaded_file函数缺少对文件目录参数的检查,远程攻击者可以利用这个函数来进行指定目录之外的文件操作。 漏洞英文描述: PHP is a commonly used HTML-embedded scripting language,which use in multiple OS.move_uploaded_file variable doesn't check the open_basedir,so the attacker can excute files out of open_based restriction by using this fuction. 漏洞参考: http://www.php.net/support.php3 http://online.securityfocus.com/archive/1/262999 http://online.securityfocus.com/archive/1/263259 http://online.securityfocus.com/archive/1/263657 系统类型:其他 漏洞类型:权限有效性检查错误