Microsoft IIS WebDAV PROPFIND and SEARCH Method Denial of Service Vulnerability
BID:7735
Info
Microsoft IIS WebDAV PROPFIND and SEARCH Method Denial of Service Vulnerability
| Bugtraq ID: | 7735 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0226 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery is credited to SPI Labs <[email protected]> and Mark Litchfield <[email protected]>. |
| Vulnerable: |
Microsoft IIS 5.1 Microsoft IIS 5.0 |
| Not Vulnerable: |
Microsoft IIS 6.0 |
Exploit / POC
Microsoft IIS WebDAV PROPFIND and SEARCH Method Denial of Service Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
There is no exploit required. The following proof-of-concept exploit have been made available:
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
There is no exploit required. The following proof-of-concept exploit have been made available:
References
Microsoft IIS WebDAV PROPFIND and SEARCH Method Denial of Service Vulnerability
References:
References:
- IIS WebDAV DoS (CORE Security)
- Microsoft Security Bulletin MS02-050 (Microsoft)
- Microsoft Security Bulletin MS03-018 (Microsoft)
- Microsoft Security Bulletin MS03-019 (Microsoft)
- IIS WebDav Denial of Service attacks - Update to SPI Dynamics ("Mark Litchfield" )
- Internet Information Services 5.0 Denial of service ("SPI Labs"
)