CNCVE编号:CNCVE-20000457 CVE编号:CVE-2000-0457 安全级别:中 漏洞中文描述: ISM.DLL in IIS 4.0和5.0中存在漏洞,该漏洞可导致远程攻击者通过请求文件并附加大量编码的空格(%20)和带有.htr的终止符来读取文件内容。 漏洞英文描述: ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via . 漏洞参考: 系统类型:其他 漏洞类型:其他