积极预防 及时发现
快速响应 力保恢复
AtomicBoard不正确处理用户提交的URI请求,远程攻击者可以利用这个漏洞以WEB权限在系统上...
发布时间:2003-07-31 信息来源:管理员

CNCVE编号:CNCVE-20031430 CVE编号: 安全级别:高 漏洞中文描述: AtomicBoard不正确处理用户提交的URI请求,远程攻击者可以利用这个漏洞以WEB权限在系统上查看任意文件内容。 漏洞英文描述: It has been reported that a script contained in paFileDB does not properly verify user credentials before accepting files for upload. As a result, remote attackers may be able to upload files to the Web server. After a file has been uploaded, it may be possible for the attacker to execute the file remotely. 漏洞参考: Reference: BUGTRAQ http://www.securityfocus.com/bid/8236 Reference: http://cal007300.student.utwente.nl/atomicboard/ 系统类型: Unix/Linux 漏洞类型:权限有效性检查错误