sa2001_02.txt...

- AV AC AU C I A
发布: 2001-05-17
修订: 2025-04-13

NSFOCUS Security Advisory SA2001-02 - The nsfocus team has found a vulnerability in filename processing of CGI program in MS IIS4.0/5.0, as discussed in ms01-026. CGI filename is decoded twice by error. Exploitation of this vulnerability leads to intruders being able to run arbitrary system commands with IUSER_machinename account privilege. Exploit URL's included.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息