CNCVE编号:CNCVE-20010137 CVE编号:CVE-2001-0137 安全级别:高 漏洞中文描述: Windows Media Player 7允许远程攻击者通过把applet封装进一个外观文件(.wmz)中,当用户在Windows Media Player的配置文件的Applet标签中设置该外观时,Windows Media Player会启用IE客户端执行恶意的JAVA applet程序。 漏洞英文描述: Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag. 漏洞参考: BID:2203 BUGTRAQ:20010115 Windows Media Player 7 and IE java vulnerability - executing arbitrary programs 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:环境错误