CNCVE编号:CNCVE-20010506 CVE编号:CAN-2001-0506 安全级别:中 漏洞中文描述: IIS 5.0和4.0的缓冲区溢出使得远程用户可以通过服务器端包含(SSI,Server-Side Includes)侦听获得系统权限,这个侦听包括了一个在有长名字的文件夹底下的文件,参看“SSI权限提高”漏洞。 漏洞英文描述: Buffer overflow in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive that includes a file that is under a directory with a long names, aka the "SSI privilege elevation" vulnerability. 漏洞参考: Reference: BUGTRAQ:20010817 NSFOCUS SA2001-06 : Microsoft IIS ssinc.dll Buffer Overflow Vulnerability Reference: MS:MS01-044 Reference: URL: