eEye Digital Security SecureIIS Attack Detection ByPass Vulnerability
BID:2742
Info
eEye Digital Security SecureIIS Attack Detection ByPass Vulnerability
| Bugtraq ID: | 2742 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2001 12:00AM |
| Updated: | May 18 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Alliance Security Labs <[email protected]> on May 17, 2001. |
| Vulnerable: |
Eeye SecureIIS 1.0.3 Eeye SecureIIS 1.0.2 |
| Not Vulnerable: |
Eeye SecureIIS 1.0.4 |
Discussion
eEye Digital Security SecureIIS Attack Detection ByPass Vulnerability
SecureIIS does not decode user requests containing URL encoded characters.
If a user submits a request containing URL encoded characters, SecureIIS will not decode the request. This issue could enable previously discovered IIS vulnerabilities to be successfully exploited on the target host without detection by SecureIIS.
SecureIIS does not decode user requests containing URL encoded characters.
If a user submits a request containing URL encoded characters, SecureIIS will not decode the request. This issue could enable previously discovered IIS vulnerabilities to be successfully exploited on the target host without detection by SecureIIS.
Exploit / POC
eEye Digital Security SecureIIS Attack Detection ByPass Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
eEye Digital Security SecureIIS Attack Detection ByPass Vulnerability
References:
References:
- SecureIIS Product Homepage (eEye Digital Security)