漏洞信息详情
CGI Script Center Auction Weaver任意文件删除漏洞
漏洞简介
Auction Weaver 1.0 到1.04版本不能正确验证表单域的名称。远程攻击者借助..(点 点)攻击删除任意文件和目录。
漏洞公告
CGI Script Center has addressed this vulnerability with the release of Auction Weaver 1.05. It is available for download at the following location: http://www.cgiscriptcenter.com/awl/
参考网址
来源: XF 名称: auction-weaver-delete-files 链接:http://xforce.iss.net/static/5371.php 来源: BID 名称: 1782 链接:http://www.securityfocus.com/bid/1782 来源: OSVDB 名称: 1600 链接:http://www.osvdb.org/1600
受影响实体
- Cgi_script_center Auction_weaver:1.04<!--2000-1-1-->
- Cgi_script_center Auction_weaver:1.03<!--2000-1-1-->
- Cgi_script_center Auction_weaver:1.02<!--2000-1-1-->
- Cgi_script_center Auction_weaver:1.01<!--2000-1-1-->
- Cgi_script_center Auction_weaver:1.0<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...