vendor:
Internet Information Services (IIS)
by:
Unknown
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Internet Information Services (IIS)
Affected Version From: Microsoft IIS 4.0
Affected Version To: Microsoft IIS 5.0
Patch Exists: YES
Related CWE: CVE-2001-0500
CPE: a:microsoft:iis:4.0, cpe:/a:microsoft:iis:5.0
Platforms Tested: Windows 98, Windows NT
2001
Microsoft IIS Double Dot Directory Traversal Vulnerability
Microsoft IIS 4.0 and 5.0 are vulnerable to double dot "../" directory traversal exploitation if extended UNICODE character representations are used in substitution for "/" and "". Unauthenticated users may access any known file in the context of the IUSR_machinename account. Successful exploitation would yield the same privileges as a user who could successfully log onto the system to a remote user possessing no credentials whatsoever."
Mitigation:
Apply the appropriate patch provided by Microsoft.