CNCVE编号:CNCVE-20020068 CVE编号: 安全级别:高 漏洞中文描述: Falcon Web Server是一个Windows系统下小型,高效的Web服务器程序。它被设计使用在小流量的桌面机器上。Falcon程序实现上存在漏洞,可以使远程攻击者绕过服务器对用户访问的验证。Falcon支持目录映射功能,用户访问需要得到主机的验证。远程攻击者可以在HTTP请求中,在要访问的受保护目录之前加上一个“/“字符,绕过服务器程序对其的验证。在低版本的Falcon软件中可能也有此漏洞。 漏洞英文描述: Falcon Web Server is a Web server for Microsoft Windows platforms that supports ISAPI and WinCGI. Falcon Web Server versions prior to 2.0.0.1021 could allow a remote attacker to bypass authentication and gain unauthorized access to protected virtual directories. If a remote attacker adds an additional forward slash character (/) prior to the path to the protected virtual directory, the attacker can bypass authentication and gain access to sensitive information. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0066.html 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误