CNCVE编号:CNCVE-20000945 CVE编号:CVE-2000-0945 安全级别:高 漏洞中文描述: Catalyst 3500 XL交换机中的网络配置接口中存在一个漏洞,该漏洞可导致远程攻击者通过一个包含/exec/目录的URL来不经认证的执行任意命令。 漏洞英文描述: The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication via a URL containing the /exec/ directory. 漏洞参考: BUGTRAQ:20001026 Advisory def-2000-02: Cisco Catalyst remote command execution | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0380.html | XF:cisco-catalyst-remote-commands | URL:http://xforce.iss.net/static/5415.php 系统类型:其他 漏洞类型:输入有效性检查错误