CNCVE编号:CNCVE-20000025 CVE编号:CVE-2000-0025 安全级别:中 漏洞中文描述: IIS 4.0和Site Server 3.0允许远程攻击者读取ASP文件的源代码,如果这些文件在名字包含例如.com, .exe, .sh, .cgi, .dll的扩展名的虚拟目录下,这就是“虚拟目录名”漏洞。 漏洞英文描述: IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. 漏洞参考: 系统类型:其他 漏洞类型:其他