CNCVE编号:CNCVE-20010523 CVE编号:CAN-2001-0523 安全级别:中 漏洞中文描述: eEye SecureIIS versions 1.0.3 及其早期版本允许远程攻击者通过在请求中使用HTML转义字符来绕过SecureIIS对请求的过滤,这使得远程攻击者使用受限的变量以及对应该另被SecureIIS保护的易受攻击的程序进行目录遍历攻击。 漏洞英文描述: eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS via the escaping of HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attack. 漏洞参考: Reference: BUGTRAQ:20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html Reference: BUGTRAQ:20010519 RE: ASLabs-2001-01: Multiple Security Problems 系统类型:其他 漏洞类型:输入有效性检查错误