CNCVE编号:CNCVE-20020069 CVE编号: 安全级别:高 漏洞中文描述: Bavo是一个开放源代码的免费新闻组阅读程序。可运行于Unix/Linux及Windows等平台下。Bavo软件包中存在一个漏洞,可能使远程攻击者可以编辑客户机上已经存在的消息邮件。问题在于Bavo对输入的过滤不充分,远程攻击者通过检查Bavo的源码得知CGI的语法,可能对已经存档的消息进行修改。 漏洞英文描述: Bavo is a freely available, open source news reader written. It is designed for use on Linux, Unix, and Microsoft operating systems. A problem with the software package could make it possible for a remote user to edit messages. The problem is in the filtering of input. It is possible for a remote user to edit messages in the Bavo archive. By examining the Bavo source and learning the CGI syntax used by Bavo, a remote user may alter the contents of archived messages. This problem makes it possible for an unauthorized remote user to alter the contents of posted messages. 漏洞参考: 系统类型:其他 漏洞类型:设计错误