Microsoft VisualInterDev 6.0 - IIS4- Management With No Authentication Vulnerability
BID:190
Info
Microsoft VisualInterDev 6.0 - IIS4- Management With No Authentication Vulnerability
| Bugtraq ID: | 190 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 1999 12:00AM |
| Updated: | Jul 12 2007 06:07PM |
| Credit: | This vulnerability was first identified and posted to NTBugtraq by Adam Berns. Follow-up research has been posted by:Charlie Roberts, Christopher Timmons, Randy Walker, and Jesper M. Johansson. |
| Vulnerable: |
Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft VisualInterDev 6.0 - IIS4- Management With No Authentication Vulnerability
Microsoft Visual InterDev 6.0 client is prone to vulnerability that permits attackers to gain unauthorized access to the affected application.
Reportedly, a Visual InterDev 6.0 client may be able to connect to an IIS4 Web Server and manage the website without requiring any user auhentication.
This issue may be associated with security permissions applied by FrontPage tools. It is unclear exactly what is allowing this to happen or under what combination of Service Pack / hotfix this may occur.
Microsoft Visual InterDev 6.0 client is prone to vulnerability that permits attackers to gain unauthorized access to the affected application.
Reportedly, a Visual InterDev 6.0 client may be able to connect to an IIS4 Web Server and manage the website without requiring any user auhentication.
This issue may be associated with security permissions applied by FrontPage tools. It is unclear exactly what is allowing this to happen or under what combination of Service Pack / hotfix this may occur.
Solution / Fix
Microsoft VisualInterDev 6.0 - IIS4- Management With No Authentication Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Microsoft VisualInterDev 6.0 - IIS4- Management With No Authentication Vulnerability
References:
References: