Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.10695
Kategorie:Web Servers
Titel:Microsoft IIS .IDA ISAPI Filter Applied - Active Check
Zusammenfassung:Indexing Service filter is enabled on the remote Web server.
Beschreibung:Summary:
Indexing Service filter is enabled on the remote Web server.

Vulnerability Insight:
The IIS server appears to have the .IDA ISAPI filter mapped.

At least one remote vulnerability has been discovered for the .IDA
(indexing service) filter. This is detailed in Microsoft Advisory
MS01-033, and gives remote SYSTEM level access to the web server.

It is recommended that even if you have patched this vulnerability that
you unmap the .IDA extension, and any other unused ISAPI extensions
if they are not required for the operation of your site.

Solution:
To unmap the .IDA extension:

1.Open Internet Services Manager.

2.Right-click the Web server choose Properties from the context menu.

3.Master Properties

4.Select WWW Service -> Edit -> HomeDirectory -> Configuration
and remove the reference to .ida from the list.

In addition, you may wish to download and install URLSCAN from the
Microsoft Technet web site. URLSCAN, by default, blocks all .ida
requests to the IIS server.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2001-0500
BugTraq ID: 2880
http://www.securityfocus.com/bid/2880
Bugtraq: 20010618 All versions of Microsoft Internet Information Services, Remote buffer overflow (SYSTEM Level Access) (Google Search)
http://www.securityfocus.com/archive/1/191873
http://www.cert.org/advisories/CA-2001-13.html
Computer Incident Advisory Center Bulletin: L-098
http://www.ciac.org/ciac/bulletins/l-098.shtml
Microsoft Security Bulletin: MS01-033
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-033
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A197
http://www.iss.net/security_center/static/6705.php
CopyrightCopyright (C) 2001 Matt Moore

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.