Microsoft ISA Server File Extension Filter Bypass Vulnerability
BID:18994
CVE-2006-3652 |Info
Microsoft ISA Server File Extension Filter Bypass Vulnerability
| Bugtraq ID: | 18994 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2006 12:00AM |
| Updated: | Jul 17 2006 08:23PM |
| Credit: | Discovery is credited to [email protected]. |
| Vulnerable: |
Microsoft ISA Server 2004 |
| Not Vulnerable: | |
Discussion
Microsoft ISA Server File Extension Filter Bypass Vulnerability
Microsoft ISA (Internet Security and Acceleration) Server is prone to a vulnerability that may let users bypass rules for filtering file extensions. Attackers could exploit this vulnerability to bypass administrative policy and to access restricted content on the Internet.
This vulnerability is reported to affect Microsoft ISA Server 2004. Other versions may also be affected.
Microsoft ISA (Internet Security and Acceleration) Server is prone to a vulnerability that may let users bypass rules for filtering file extensions. Attackers could exploit this vulnerability to bypass administrative policy and to access restricted content on the Internet.
This vulnerability is reported to affect Microsoft ISA Server 2004. Other versions may also be affected.
Exploit / POC
Microsoft ISA Server File Extension Filter Bypass Vulnerability
This issue can be exploited via a web browser.
This issue can be exploited via a web browser.
Solution / Fix
Microsoft ISA Server File Extension Filter Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Microsoft ISA Server File Extension Filter Bypass Vulnerability
References:
References: