积极预防 及时发现
快速响应 力保恢复
WebCalendar不正确处理用户提交的URI请求,远程攻击者可以利用这个漏洞以WEB进程权限在系...
发布时间:2003-07-31 信息来源:管理员

CNCVE编号:CNCVE-20031435 CVE编号: 安全级别:高 漏洞中文描述: WebCalendar不正确处理用户提交的URI请求,远程攻击者可以利用这个漏洞以WEB进程权限在系统上查看任意文件内容。 漏洞英文描述: It has been reported that an information disclosure issue exists in WebCalendar. This may allow an attacker to gain unauthorized read access to potentially sensitive information with the privileges of the web server process. 漏洞参考: Reference: http://marc.theaimsgroup.com/?l=bugtraq&m=105880851102756&w=2 Reference: http://www.securityfocus.com/bid/8237 系统类型: Unix/Linux 漏洞类型:输入有效性检查错误