CNCVE编号:CNCVE-20010712 CVE编号:CAN-2001-0712 安全级别:高 漏洞中文描述: Internet Explorer提供的引擎从由服务器指定的类型中独立的确定MIME类型,这导致了远程服务器自动的执行放置在文件中的代码,而原先这些文件的MIME类型并不能正常的支持这些代码,如 :文本文件(.txt),JPEG(.jpg)文件等。 漏洞英文描述: The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally suppor 漏洞参考: Reference: BUGTRAQ:20010727 TXT or HTML? -- IE NEW BUG Reference: URL:http://www.securityfocus.com/archive/1/200109 Reference: BUGTRAQ:20010729 Re: TXT or HTML? -- IE NEW BUG Reference: URL:http://www.securityfocus.com/archive/1/200291 Reference: BID: 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误