Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft IIS示例脚本CodeBrws.asp远程读取特定脚本源码漏洞
Vulnerability Description
Microsoft IIS(Internet Information Server)是MS Windows系统默认自带的Web服务器软件。 IIS 5.0默认自带的示例脚本文件CodeBrws.asp对用户输入没有正确过滤,远程攻击者可能利用此漏洞读取Web主目录内任意以.asp、.inc、.htm和.html为后缀的文件。 问题在于CodeBrws.asp脚本中虽然对提交给它参数的路径信息中检查是否包含了".."串,但没有考虑到Unicode的可能,远程攻击者可能提交".."串的Unicode表示方式"
CVSS Information
N/A
Vulnerability Type
N/A