ms00-086...

- AV AC AU C I A
发布: 2000-12-03
修订: 2025-04-13

Microsoft Security Bulletin (MS00-086) - Microsoft has released a patch that eliminates a serious security vulnerability in Microsoft IIS 5.0. Due to an implementation flaw, it is possible to create a specially-malformed file request that contains both a file name and one or more operating system commands. Upon receiving such a request, IIS 5.0 passes the entire string to the operating system, which would first process the file and then execute the commands with user priveledge. Microsoft FAQ on this issue available here.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息