CGIHTML Form Data File Corruption...

- AV AC AU C I A
发布: 2003-01-07
修订: 2025-04-13

When handling uploaded form-data, cgihtml creates a temporary file to store this data in /tmp or another user-specified directory. The software uses the client supplied filename when creating the temporary file. If the client supplies a malicious filename (such as one containing directory traversal sequences), it may be able to overwrite local files on the system hosting the vulnerable software.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息