CNCVE编号:CNCVE-20010524 CVE编号:CAN-2001-0524 安全级别:中 漏洞中文描述: eEye SecureIIS versions 1.0.3 及其早期版本不能在个别的HTTP报头上执行长度校验,这允许远程攻击者对IIS发送任意长度的字符串,这与SecureIIS versions 1.0.3及其早期版本的advertised功能相反。 漏洞英文描述: eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier. 漏洞参考: Reference: BUGTRAQ:20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html Reference: BUGTRAQ:20010519 RE: ASLabs-2001-01: Multiple Security Problems 系统类型:其他 漏洞类型:输入有效性检查错误