积极预防 及时发现
快速响应 力保恢复
Internet Explorer 5.0到5.5版本里用于调用scriptlet的ActiveX控...
发布时间:2001-02-16 信息来源:管理员

CNCVE编号:CNCVE-20010091 CVE编号:CVE-2001-0091 安全级别:中 漏洞中文描述: Internet Explorer 5.0到5.5版本里用于调用scriptlet的ActiveX控件提供了替代HTML的任意文件类型,这将导致攻击者可以阅读任意的文件。 漏洞英文描述: The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability. 漏洞参考: MS:MS00-093 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误