IIS代码注入漏洞

IIS代码注入漏洞

漏洞ID 1105300 漏洞类型 其他
发布时间 1997-02-20 更新时间 1999-12-31
图片[1]-IIS代码注入漏洞-安全小百科CVE编号 CVE-1999-0154
图片[2]-IIS代码注入漏洞-安全小百科CNNVD-ID CNNVD-199912-153
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/20481
https://www.securityfocus.com/bid/80405
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199912-153
|漏洞详情
Microsoft Internet Information Services(IIS)是美国微软(Microsoft)公司的一款适用于Windows Server平台的Web服务器。
Microsoft Internet Information Services 2.0及3.0中存在安全漏洞。远程攻击者通过在URL末尾附加.(点)读取ASP页的源代码。

|漏洞EXP
source: http://www.securityfocus.com/bid/2074/info

Microsoft Internet Information Server (IIS) is a popular web server, providing support for a variety of scripting languages, including ASP (active server pages). IIS 2.0 and 3.0 suffer from an issue allowing a remote user to retrieve the source code for any script (that has read permissions on the server) via a web browser. This is accomplished by appending a period (.) to the end of a URL requesting a specific script, and applies to any file types in the "script-map list", including .asp, .ht., .id, .PL, and others. Consequences of exploitation vary depending on the site design, but commonly include details of directory structure on the web server, database passwords, and various other pieces of information that could then be used to mount further attacks. A Microsoft hotfix for this issue was released, but has been found vulnerable to a variation whereby the period is replaced by %2e, the hexadecimal encoding for the same character. (BugTraq ID 1814). 

http://www.target.host/aspfile.asp.
http://www.target.host/scriptfile.ht.
http://www.target.host/scriptfile.id.
http://www.target.host/scriptfile.PL.
|受影响的产品
Microsoft IIS 3.0

Microsoft Windows NT 4.0 SP6a

Microsoft Windows NT 4.0 SP6a

Microsoft Windows NT 4.0 SP6

|参考资料
VulnerablesoftwareandversionsConfiguration1OR*cpe:/a:microsoft:internet_information_server:2.0*cpe:/a:microsoft:internet_information_server:3.0*DenotesVulnerableSoftware*ChangesrelatedtovulnerabilityconfigurationsTechnicalDetailsVulnerabilityType(ViewAll)CVEStandardVulnerabilityEntry:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0154

相关推荐: Microsoft IIS 4.0 Domain Resolution Vulnerability

Microsoft IIS 4.0 Domain Resolution Vulnerability 漏洞ID 1104594 漏洞类型 Access Validation Error 发布时间 1999-09-23 更新时间 1999-09-23 CVE编号 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享