eEye Digital Security SecureIIS Possible Information Leakage Vulnerability
BID:2747
Info
eEye Digital Security SecureIIS Possible Information Leakage Vulnerability
| Bugtraq ID: | 2747 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2001 12:00AM |
| Updated: | May 18 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Alliance Security Labs <[email protected]> on May 18, 2001. |
| Vulnerable: |
Eeye SecureIIS 1.0.2 |
| Not Vulnerable: |
Eeye SecureIIS 1.0.4 Eeye SecureIIS 1.0.3 |
Discussion
eEye Digital Security SecureIIS Possible Information Leakage Vulnerability
It has been reported that SecureIIS exhibits strange behaviour when it recieves large requests (composed of several thousand characters). One of the behaviours that has been reportedly observed is the disclosure of internal memory on error pages in response to excessive requests. The original report stated that in one instance, information about the configuration was disclosed to the attacker sending the request.
This may assist attackers in further attacks against the server and network.
Further information is forthcoming.
It has been reported that SecureIIS exhibits strange behaviour when it recieves large requests (composed of several thousand characters). One of the behaviours that has been reportedly observed is the disclosure of internal memory on error pages in response to excessive requests. The original report stated that in one instance, information about the configuration was disclosed to the attacker sending the request.
This may assist attackers in further attacks against the server and network.
Further information is forthcoming.
Exploit / POC
eEye Digital Security SecureIIS Possible Information Leakage Vulnerability
No exploit code is required to demonstrate this vulnerability. Tools such as netcat can be used to send large requests to the target webserver.
No exploit code is required to demonstrate this vulnerability. Tools such as netcat can be used to send large requests to the target webserver.
Solution / Fix
eEye Digital Security SecureIIS Possible Information Leakage Vulnerability
Solution:
Update available:
Eeye SecureIIS 1.0.2
Solution:
Update available:
Eeye SecureIIS 1.0.2
-
eEye Digital Security SecureIIS v1.0.4
http://www.eeye.com/secureiis
References
eEye Digital Security SecureIIS Possible Information Leakage Vulnerability
References:
References:
- SecureIIS Product Homepage (eEye Digital Security)