CNCVE编号:CNCVE-20011020 CVE编号:CVE-2001-1020 安全级别:中 漏洞中文描述: 0.91之前的Vibechild Directory Manager中的edit_image.php允许远程攻击者通过在userfile_name参数中的shell 元字符来执行任意命令,它被不经过滤的送到PHP的passthru函数。 漏洞英文描述: edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function. 漏洞参考: 系统类型:其他 漏洞类型:其他