CNCVE编号:CNCVE-20010537 CVE编号:CAN-2001-0537 安全级别:高 漏洞中文描述: 当本地认证正在使用时,用于Cisco IOS 11.3到 12.2的HTTP服务器允许远程攻击者通过“...”(改进的“..”)来绕过认证以及执行任意命令。 漏洞英文描述: HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, via a .... (modified dot dot) in the URL. 漏洞参考: CISCO:20010627 IOS HTTP authorization vulnerability URL:http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html CERT:CA-2001-14 URL:http://www.cert.org/advisories/CA-2001-14.html 系统类型: 其他 漏洞类型:输入有效性检查错误