Microsoft IIS 6.0的WEB管理接口存在多个问题,远程攻击者可以利用这个漏洞进行跨站脚... & `* z4 B0 r# x9 m9 H5 H- E& u来源:CNCERT 2003-08-01 & O, p# M( P; N) q
9 s' Y+ h. g/ v7 Q X2 x7 ~
0 P/ E4 T5 ` L% J4 q/ Y( DCNCVE编号:CNCVE-20031438 : q# d/ N7 Z5 v/ s0 Y7 c6 f . i8 J/ s1 C. mCVE编号:( o S/ ~8 u" ^8 u' H
0 |1 c3 M4 u4 O2 d& a
安全级别:高( T! R. Z! {- C; P0 i2 j3 |
- t4 A* `4 Z' E, n! O: q1 I
漏洞中文描述:, r. X+ E9 Y* V/ x" O
Microsoft IIS 6.0的WEB管理接口存在多个问题,远程攻击者可以利用这个漏洞进行跨站脚本攻击,获得合法会话ID或未授权访问部分资源。' [) v2 c+ A. C5 d8 N
U: H" s! @1 x
漏洞英文描述: 8 Z! e& S* B# }0 T: R! MMultiple vulnerabilities have been reported in the web admin interface that is included in Microsoft IIS 6.0. This includes multiple instances of cross-site scripting vulnerabilities. Additionally, it is reported that the web admin interface could expose valid session IDs or permit unauthorized access to areas that do not require session IDs.5 e* h/ h% L0 ~) M" w
- w `3 b! @; g
漏洞参考: ! O: l9 S% d" T" {& rhttp://www.securityfocus.com/bid/82444 E, u8 B; Q h4 v& ]
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com