积极预防 及时发现
快速响应 力保恢复
Internet Explorer 5.5及其早期版本使用网站指定的命令行参数执行远程登录会话,如果...
发布时间:2001-06-02 信息来源:管理员

CNCVE编号:CNCVE-20010150 CVE编号:CVE-2001-0150 安全级别:高 漏洞中文描述: Internet Explorer 5.5及其早期版本使用网站指定的命令行参数执行远程登录会话,如果IE客户正在使用用于为Unix(SFU)2.0创建会话抄本的服务所提供的Telnet客户端的话,这可能导致远程攻击者执行任意命令。 漏洞英文描述: Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Service copy session in Unix(SFU)2.0. 漏洞参考: Reference: MS:MS01-015 Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-015.asp 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误