Microsoft IIS 3.0/4.0 – Upgrade BDIR.HTR

Microsoft IIS 3.0/4.0 – Upgrade BDIR.HTR

漏洞ID 1053379 漏洞类型
发布时间 1998-12-25 更新时间 1998-12-25
图片[1]-Microsoft IIS 3.0/4.0 – Upgrade BDIR.HTR-安全小百科CVE编号 N/A
图片[2]-Microsoft IIS 3.0/4.0 – Upgrade BDIR.HTR-安全小百科CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/20590
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/2280/info

Microsoft Internet Information Server (IIS) 3.0 came with a series of remote administration scripts installed in /scripts/iisadmin off the web root directory. ism.dll is required for processing these scripts, and version 3.0 of IIS came with an ism.dll containing an authentication scheme to prevent unauthorized access. If an IIS 3.0 installation is upgraded to IIS 4.0 without removing these scripts, they can be accessed remotely without authentication due to changes in the authentication methods used by IIS 4.0. One of these scripts, bdir.htr, still functions under the IIS 4.0 server - and can be used by a remote attacker to obtain information about the server's directory structure. The script displays a directory listing of a directory specified as part of a request - but only directory names are displayed. Although privilege elevation cannot be accomplished directly by exploiting this script, the information about the server's directory structure thus obtained could potentially be used in mounting further attacks.

This can be exploited by requesting the following from the web server:

http://victim/scripts/iisadmin/bdir.htr??<path>

eg.,

http://www.victim-host.xxx/scripts/iisadmin/bdir.htr??d:webs

相关推荐: IRIX ordist Vulnerability

IRIX ordist Vulnerability 漏洞ID 1105069 漏洞类型 Boundary Condition Error 发布时间 1997-05-24 更新时间 1997-05-24 CVE编号 N/A CNNVD-ID N/A 漏洞平台 N…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享