CVE-2009-1122
Summary
| CVE | CVE-2009-1122 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-06-10 18:30:00 UTC |
| Updated | 2020-11-23 20:06:00 UTC |
| Description | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Information Services | 5.0 | All | All | All |
| Application | Microsoft | Internet Information Services | 5.0 | All | All | All |
| Operating System | Microsoft | Windows 2000 | - | sp4 | All | All |
| Operating System | Microsoft | Windows 2000 | - | sp4 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft IIS 5.0 WebDAV Authentication Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | Third Party Advisory |
| US-CERT Technical Cyber Security Alert TA09-160A -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| [VIM] IIS WebDav Vulnerability CVE ID | VIM | www.attrition.org | Third Party Advisory |
| Microsoft Internet Information Services WebDAV Bug Lets Remote Users Bypass Authentication - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Microsoft Security Bulletin MS09-020 - Important | Microsoft Docs | MS | docs.microsoft.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.