积极预防 及时发现
快速响应 力保恢复
IIS4.0和5.0 .ASP网页发送同一用于安全的和不安全的网络会话的ID会话cookie,这种做...
发布时间:2000-12-19 信息来源:管理员

CNCVE编号:CNCVE-20000970 CVE编号:CVE-2000-0970 安全级别:中 漏洞中文描述: IIS4.0和5.0 .ASP网页发送同一用于安全的和不安全的网络会话的ID会话cookie,这种做法使得远程攻击者在用户在安全会话后使用不安全的会话后可以劫持用户的安全网络会话。 漏洞英文描述: IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" 漏洞参考: MS:MS00-080 | URL:http://www.microsoft.com/technet/security/bulletin/ms00-080.asp | XF:session-cookie-remote-retrieval | URL:http://xforce.iss.net/static/5396.php 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:权限有效性检查错误