CNCVE编号:CNCVE-20010333 CVE编号:CVE-2001-0333 安全级别:高 漏洞中文描述: 在IIS5.0和之前版本中的文件遍历漏洞允许远程攻击者通过“..”和两个“”字符编码来执行任何命令。 漏洞英文描述: Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. 漏洞参考: BUGTRAQ:20010515 NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98992056521300&w=2 MS:MS01-026 URL:http://www.microsoft.com/technet/security/bulletin/MS01-026.asp 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误