Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.10671
Kategorie:Web Servers
Titel:Microsoft IIS Remote Command Execution (MS01-026/MS01-044) - Active Check
Zusammenfassung:When IIS receives a user request to run a script, it renders; the request in a decoded canonical form, then performs security checks on the decoded request.
Beschreibung:Summary:
When IIS receives a user request to run a script, it renders
the request in a decoded canonical form, then performs security checks on the decoded request.

Vulnerability Insight:
A vulnerability results because a second, superfluous decoding pass is
performed after the initial security checks are completed. Thus, a specially crafted request could allow
an attacker to execute arbitrary commands on the IIS Server.

Solution:
See MS advisory MS01-026 (Superseded by MS01-044).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2001-0507
Bugtraq: 20010816 ENTERCEPT SECURITY ALERT: Privilege Escalation Vulnerability in Microsoft IIS (Google Search)
http://online.securityfocus.com/archive/1/205069
Computer Incident Advisory Center Bulletin: L-132
http://www.ciac.org/ciac/bulletins/l-132.shtml
Microsoft Security Bulletin: MS01-044
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044
http://www.osvdb.org/5607
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A909
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A912
XForce ISS Database: iis-relative-path-privilege-elevation(6985)
https://exchange.xforce.ibmcloud.com/vulnerabilities/6985
Common Vulnerability Exposure (CVE) ID: CVE-2001-0333
BugTraq ID: 2708
http://www.securityfocus.com/bid/2708
Bugtraq: 20010515 NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=98992056521300&w=2
http://www.cert.org/advisories/CA-2001-12.html
Microsoft Security Bulletin: MS01-026
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-026
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1018
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1051
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A37
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A78
XForce ISS Database: iis-url-decoding(6534)
https://exchange.xforce.ibmcloud.com/vulnerabilities/6534
CopyrightCopyright (C) 2001 Matt Moore / HD Moore

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.