CNCVE编号:CNCVE-20010398 CVE编号:CAN-2001-0398 安全级别:高 漏洞中文描述: BAT! 邮件客户程序允许远程攻击者通过一个文件名中含有很多空格的附件名来绕过一个可执行附件的用户警告以及执行任意命令,同时也会引发BAT! 误称带有不同图标的附件类型。 漏洞英文描述: The BAT! Mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! To misrepresent the attachment's type with different icons. 漏洞参考: BUGTRAQ:20010402 ~..~!guano URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0013.html BID:2530 URL:http://www.securityfocus.com/bid/2530 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:其他