积极预防 及时发现
快速响应 力保恢复
CVSWeb 1.80中的cvsweb CGI脚本允许对CVS知识库具有写访问权限的远程攻击者通过s...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000670 CVE编号:CVE-2000-0670 安全级别:中 漏洞中文描述: CVSWeb 1.80中的cvsweb CGI脚本允许对CVS知识库具有写访问权限的远程攻击者通过shell元字符执行任意命令。 漏洞英文描述: The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters. 漏洞参考: 系统类型:其他 漏洞类型:其他