Microsoft IIS File Enumeration Weakness
BID:54251
Info
Microsoft IIS File Enumeration Weakness
| Bugtraq ID: | 54251 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2012 12:00AM |
| Updated: | Jun 30 2012 12:00AM |
| Credit: | Soroush Dalili |
| Vulnerable: |
Microsoft IIS 7.5 Microsoft IIS 6.0 Microsoft IIS 5.0 Microsoft IIS 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS File Enumeration Weakness
Microsoft IIS is prone to a file-enumeration weakness because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to enumerate the files present in the webserver's root directory; this may aid in further attacks.
Microsoft IIS is prone to a file-enumeration weakness because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to enumerate the files present in the webserver's root directory; this may aid in further attacks.
Exploit / POC
Microsoft IIS File Enumeration Weakness
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Microsoft IIS File Enumeration Weakness
Solution:
Reportedly, the issue has been fixed in the latest versions of application. Please contact the vendor for more information.
Solution:
Reportedly, the issue has been fixed in the latest versions of application. Please contact the vendor for more information.