Microsoft BizTalk Server Documentation/WebDAV Weak Permissions Vulnerability
BID:8661
Info
Microsoft BizTalk Server Documentation/WebDAV Weak Permissions Vulnerability
| Bugtraq ID: | 8661 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2003 12:00AM |
| Updated: | Sep 19 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Cesar <[email protected]>. |
| Vulnerable: |
Microsoft Biztalk Server 2002 Partner Edition 0 Microsoft BizTalk Server 2002 Enterprise Edition Microsoft BizTalk Server 2002 Developer Edition Microsoft BizTalk Server 2000 Standard Edition SP2 Microsoft BizTalk Server 2000 Standard Edition SP1a Microsoft BizTalk Server 2000 Standard Edition Microsoft BizTalk Server 2000 Enterprise Edition SP2 Microsoft BizTalk Server 2000 Enterprise Edition SP1a Microsoft BizTalk Server 2000 Enterprise Edition Microsoft BizTalk Server 2000 Developer Edition SP2 Microsoft BizTalk Server 2000 Developer Edition SP1a Microsoft BizTalk Server 2000 Developer Edition |
| Not Vulnerable: | |
Discussion
Microsoft BizTalk Server Documentation/WebDAV Weak Permissions Vulnerability
It has been reported that Microsoft BizTalk Server is prone to a weak permissions vulnerability due to a configuration error in the BizTalkServerDocs and BizTalkServerRepository virtual directories.
Successful exploitation of this issue may allow an attacker to replace or modify HTML and XML files stored on the server by attacker-supplied arbitrary files.
It has been reported that Microsoft BizTalk Server is prone to a weak permissions vulnerability due to a configuration error in the BizTalkServerDocs and BizTalkServerRepository virtual directories.
Successful exploitation of this issue may allow an attacker to replace or modify HTML and XML files stored on the server by attacker-supplied arbitrary files.