CNCVE编号:CNCVE-20001105 CVE编号:CAN-2000-1105 安全级别:中 漏洞中文描述: ixsso.query ActiveX Object标识为脚本安全,这允许恶意的网站操作者通过嵌入脚本,来远程确定所访问的已启动索引服务的Windows2000系统上是否存在攻击者想要查找的文件。 漏洞英文描述: The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. 漏洞参考: BUGTRAQ:20001110 IE 5.x Win2000 Indexing service vulnerability | URL:http://www.securityfocus.com/archive/1/144270 | WIN2KSEC:20001110 IE 5.x Win2000 Indexing service vulnerability | URL:http://archives.neohapsis.com/archives/win2ksecadvice/20 系统类型: Win2000/NT 漏洞类型:权限有效性检查错误