![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2014-4078 |
Description: | The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list, which makes it easier for remote attackers to bypass an intended rule set via an HTTP request, aka "IIS Security Feature Bypass Vulnerability." |
Test IDs: | 1.3.6.1.4.1.25623.1.0.805016 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-4078 BugTraq ID: 70937 http://www.securityfocus.com/bid/70937 Microsoft Security Bulletin: MS14-076 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-076 http://www.securitytracker.com/id/1031194 |