CNCVE编号:CNCVE-20001147 CVE编号:CAN-2000-1147 安全级别:高 漏洞中文描述: IIS ISAPI .ASP解析机制中的缓冲区溢出允许攻击者通过在脚本标签的“LANGUAGE”参数中设置长字符串来执行任意的命令。 漏洞英文描述: Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag. 漏洞参考: BUGTRAQ:20001103 IIS ASP $19.95 hack - IISHack 1.5 | URL:http://www.securityfocus.com/archive/1/143070 | BID:1911 | URL:http://www.securityfocus.com/bid/1911 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误