CNCVE编号:CNCVE-20000720 CVE编号:CVE-2000-0720 安全级别:中 漏洞中文描述: 在GWScripts News Publisher中的news.cgi没有完全验证向作者索引加入一个作者的请求,这导致远程攻击者可以通过直接向带有addAuthor参数的new.cgi程序传送HTTP请求来加入新的作者,以及对new.cgi程序设置提交。 漏洞英文描述: news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and request for new.cgi program setting. 漏洞参考: 系统类型:其他 漏洞类型:其他