积极预防 及时发现
快速响应 力保恢复
在Lotus Notes 5.02 以前的版本中的缺省ECL允许远程攻击者通过在邮件消息中附加一个...
发布时间:2001-07-21 信息来源:管理员

CNCVE编号:CNCVE-20000891 CVE编号:CAN-2000-0891 安全级别:高 漏洞中文描述: 在Lotus Notes 5.02 以前的版本中的缺省ECL允许远程攻击者通过在邮件消息中附加一个恶意程序来执行任何命令,当用户打开邮件时,此恶意程序自动执行。 漏洞英文描述: A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email. 漏洞参考: CERT-VN:VU#5962 URL:http://www.kb.cert.org/vuls/id/5962 CONFIRM:http://www.notes.net/R5FixList.nsf/Search!SearchView&Query=CBAT45TU9S 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误