积极预防 及时发现
快速响应 力保恢复
MailForm 2.0中的mailform.pl CGI脚本允许远程攻击者通过在XX-attach...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000877 CVE编号:CVE-2000-0877 安全级别:中 漏洞中文描述: MailForm 2.0中的mailform.pl CGI脚本允许远程攻击者通过在XX-attach_file参数中指定文件名来读取任意文件,然后由MailForm发送给攻击者。 漏洞英文描述: mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker. 漏洞参考: 系统类型:其他 漏洞类型:其他