标题: IIS 6.0的WEB管理接口存在多个问题 [打印本页] 作者: 韩冰 时间: 2004-10-9 14:26 标题: IIS 6.0的WEB管理接口存在多个问题 Microsoft IIS 6.0的WEB管理接口存在多个问题,远程攻击者可以利用这个漏洞进行跨站脚... $ B' Y( s& b% e+ c* T- y9 I6 ~ H) _来源:CNCERT 2003-08-01 5 r* \1 g! Q; i' ^7 ^8 b / V2 r! ^2 n+ ? J4 i4 Y) R. ~. {, ^* F6 a. q% ?# w
CNCVE编号:CNCVE-200314386 _- Y5 U1 o3 ^% I
0 C# g% B( ?8 I* dCVE编号:- i8 ~, @# Z4 i# G" h
, j& X+ p/ S% a# E8 f0 Q/ `
安全级别:高 " g& B5 {! E; l7 {) \4 X ' W" u2 c: v! F5 a; A$ |8 O漏洞中文描述: / u+ L* ~- l$ K, h+ lMicrosoft IIS 6.0的WEB管理接口存在多个问题,远程攻击者可以利用这个漏洞进行跨站脚本攻击,获得合法会话ID或未授权访问部分资源。 " m3 Z5 _, e- @) S5 x ? # M/ E5 ~6 H1 ^4 G# i3 r% q漏洞英文描述: ; c4 l2 p8 J: ]6 l& J& zMultiple vulnerabilities have been reported in the web admin interface that is included in Microsoft IIS 6.0. This includes multiple instances of cross-site scripting vulnerabilities. Additionally, it is reported that the web admin interface could expose valid session IDs or permit unauthorized access to areas that do not require session IDs.9 k+ z2 A$ d" n) l
, _! u. |) L4 h) H, F! i漏洞参考: / { d# f r$ j* jhttp://www.securityfocus.com/bid/8244 + P: J" |) e1 `/ i ' [4 C( y1 W) d8 z8 U& S系统类型: Win2000/NT " l7 [5 |1 w# p
& T, o9 B6 E- [+ y
漏洞类型:其他作者: ilikenba 时间: 2004-10-19 20:12
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com