Microsoft IIS 6.0的WEB管理接口存在多个问题,远程攻击者可以利用这个漏洞进行跨站脚... 0 u2 v% t1 ~# e5 a, }, N" k( W" h来源:CNCERT 2003-08-01 ( S% c# d; `& D9 I. g: f( l7 M( ]* e4 d; p- k4 l& C
; i+ K. M, E) Y# b* o/ |2 ~CNCVE编号:CNCVE-200314380 b/ t! w! ]- C! W
0 b- [* e: e, _# X Y
CVE编号:8 x& `6 ?: f: c+ C; V
; y" q4 |% p% N" u2 E安全级别:高 , N+ X* q! Z4 Z2 @8 n+ @ ( M9 M( U" R) q7 X- a漏洞中文描述: & T8 y U- `( pMicrosoft IIS 6.0的WEB管理接口存在多个问题,远程攻击者可以利用这个漏洞进行跨站脚本攻击,获得合法会话ID或未授权访问部分资源。, F' F/ J; V% m' r+ N
; G' _6 T m; l, A" @漏洞英文描述:4 N+ F* |: h2 m4 `0 n
Multiple vulnerabilities have been reported in the web admin interface that is included in Microsoft IIS 6.0. This includes multiple instances of cross-site scripting vulnerabilities. Additionally, it is reported that the web admin interface could expose valid session IDs or permit unauthorized access to areas that do not require session IDs.( K( ~9 S% ?5 x5 h# x) {
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com