CNCVE编号:CNCVE-20010507 CVE编号:CAN-2001-0507 安全级别:高 漏洞中文描述: IIS5.0使用相对路径来搜索在进程中运行的系统文件,这允许本地用户通过木马文件获得权限,参看“系统文件列表权限提升”漏洞。 漏洞英文描述: IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability. 漏洞参考: Reference: MS:MS01-044 Reference: URL: