积极预防 及时发现
快速响应 力保恢复
Microsoft Index Server允许远程攻击者通过在CiWebHitsFile参数(此参...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000302 CVE编号:CVE-2000-0302 安全级别:中 漏洞中文描述: Microsoft Index Server允许远程攻击者通过在CiWebHitsFile参数(此参数发往null.htw URL)的文件名中增加一个%20来查看ASP文件的源代码。 漏洞英文描述: Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL. 漏洞参考: 系统类型:其他 漏洞类型:其他