CNCVE编号:CNCVE-20031429 CVE编号: 安全级别:中 漏洞中文描述: paFileDB不正确验证上传文件的用户信息,远程攻击者可以利用这个漏洞上传任意文件到系统并执行。 漏洞英文描述: It has been reported that a script contained in paFileDB does not properly verify user credentials before accepting files for upload. As a result, remote attackers may be able to upload files to the Web server. After a file has been uploaded, it may be possible for the attacker to execute the file remotely. 漏洞参考: Reference: BUGTRAQ http://www.securityfocus.com/bid/8271 Reference: http://marc.theaimsgroup.com/?l=bugtraq&m=105906835422386&w=2 系统类型: 其他 漏洞类型:权限有效性检查错误