Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.15714
Category:Windows : Microsoft Bulletins
Title:ISA Server 2000 and Proxy Server 2.0 Internet Content Spoofing (888258)
Summary:The ISA Server 2000 and Proxy Server 2.0 have been found to be vulnerable to; a spoofing vulnerability that could enable an attacker to spoof trusted Internet; content. Users could believe they are accessing trusted Internet content when; in reality they are accessing malicious Internet content, for example a; malicious Web site. However, an attacker would first have to persuade a user to; visit the attacker's to attempt to exploit this vulnerability.
Description:Summary:
The ISA Server 2000 and Proxy Server 2.0 have been found to be vulnerable to
a spoofing vulnerability that could enable an attacker to spoof trusted Internet
content. Users could believe they are accessing trusted Internet content when
in reality they are accessing malicious Internet content, for example a
malicious Web site. However, an attacker would first have to persuade a user to
visit the attacker's to attempt to exploit this vulnerability.

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore.
General solution options are to upgrade to a newer release, disable respective features,
remove the product or replace the product by another one.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0892
BugTraq ID: 11605
http://www.securityfocus.com/bid/11605
Microsoft Security Bulletin: MS04-039
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-039
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4264
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4859
XForce ISS Database: isa-cache-reverse-spoof(17906)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17906
CopyrightCopyright (C) 2004 Jeff Adams

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.