Microsoft URLScan / RSA Security SecurID Configuration Enumeration Weakness

BID:8419

Info

Microsoft URLScan / RSA Security SecurID Configuration Enumeration Weakness

Bugtraq ID: 8419
Class: Configuration Error
CVE:
Remote: Yes
Local: No
Published: Aug 14 2003 12:00AM
Updated: Aug 14 2003 12:00AM
Credit: The discovery of this weakness has been credited to Andy Davis.
Vulnerable: Rsa SecurID 5.0
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
Microsoft URLScan 2.5
Not Vulnerable:

Discussion

Microsoft URLScan / RSA Security SecurID Configuration Enumeration Weakness

A weakness has been discovered in Microsoft URLScan and RSA Security SecurID when used in conjunction on a web server. The problem is said to occur due to the order in which the products are placed within the global ISAPI filter list.

When the vulnerable configuration is in place, an attacker may be capable of enumerating the Microsoft URLScan extension filtering list by making repeated requests to files with differing extensions.

The enumeration of this type of information could potentially aid an attacker when launching further attacks against the target web server.

Exploit / POC

Microsoft URLScan / RSA Security SecurID Configuration Enumeration Weakness

IRM has released a script designed to automate the process of requesting a multitude of file extensions and enumerate the configuration settings of Microsoft URLScan. The script was written by Andy Davis.

Solution / Fix

Microsoft URLScan / RSA Security SecurID Configuration Enumeration Weakness

Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

References

Microsoft URLScan / RSA Security SecurID Configuration Enumeration Weakness

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report