Microsoft Internet Information Services Remote Script Code Execution Vulnerability
BID:43561
Info
Microsoft Internet Information Services Remote Script Code Execution Vulnerability
| Bugtraq ID: | 43561 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2010 12:00AM |
| Updated: | Sep 28 2010 12:00AM |
| Credit: | Juan Galiana |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Microsoft Internet Information Services Remote Script Code Execution Vulnerability
Microsoft Internet Information Services (IIS) is prone to a vulnerability that lets attackers execute arbitrary code. The problem occurs because IIS fails to properly sanitize user-supplied input when parsing directory names.
An attacker may leverage this issue to execute arbitrary script code on an affected computer in the context of the webserver process.
Microsoft IIS 6.0 is vulnerable; other versions may also be affected.
Microsoft Internet Information Services (IIS) is prone to a vulnerability that lets attackers execute arbitrary code. The problem occurs because IIS fails to properly sanitize user-supplied input when parsing directory names.
An attacker may leverage this issue to execute arbitrary script code on an affected computer in the context of the webserver process.
Microsoft IIS 6.0 is vulnerable; other versions may also be affected.
Exploit / POC
Microsoft Internet Information Services Remote Script Code Execution Vulnerability
Attackers must have the ability to upload files to an affected server to exploit this issue.
Attackers must have the ability to upload files to an affected server to exploit this issue.
Solution / Fix
Microsoft Internet Information Services Remote Script Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Information Services Remote Script Code Execution Vulnerability
References:
References:
- IIS6/ASP & file upload ( Juan Galiana)
- Microsoft IIS Homepage (Microsoft)