CNCVE编号:CNCVE-20000884 CVE编号:CVE-2000-0884 安全级别:中 漏洞中文描述: IIS4.0和5.0中存在一个漏洞,该漏洞导致远程攻击者通过一些特定形式的URL来读取网络根目录外的文件,这些URL包含UNICODE编码的字符。 漏洞英文描述: IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. 漏洞参考: BUGTRAQ:20001017 IIS %c1%1c remote command execution | MS:MS00-078 | URL:http://www.microsoft.com/technet/security/bulletin/ms00-078.asp | BID:1806 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误