) ]9 E. r- ?/ h& p- M安全级别:高5 j0 C7 ~5 j/ D/ I' {
5 r. V; o' U: k1 l9 W8 y
漏洞中文描述: 6 g1 S: ~8 N" A! h2 {Microsoft IIS 6.0的WEB管理接口存在多个问题,远程攻击者可以利用这个漏洞进行跨站脚本攻击,获得合法会话ID或未授权访问部分资源。$ w N' @, G8 t& `" k/ U3 N4 R
2 O+ d# T* U- y9 e }. e& J
漏洞英文描述: 5 e+ e+ W. d1 m( g$ {& v0 y, tMultiple vulnerabilities have been reported in the web admin interface that is included in Microsoft IIS 6.0. This includes multiple instances of cross-site scripting vulnerabilities. Additionally, it is reported that the web admin interface could expose valid session IDs or permit unauthorized access to areas that do not require session IDs. C6 H; f4 i8 Z9 T; a) F( V8 P0 O# n! U. O7 R/ A
漏洞参考:% F, s0 y% [# ~* Z1 h9 \+ u7 h8 L
http://www.securityfocus.com/bid/8244( B- P6 K6 Q; Z1 V- |
! q, `' |! u2 D" B/ P* T系统类型: Win2000/NT 4 A/ Y+ C3 m7 L& h$ C5 P, a2 w
. ?* L9 K5 j6 Q' A$ m% P
漏洞类型:其他
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com