vendor:
IIS 6
by:
Racle@tian6.com && Securiteweb.org
7,5
CVSS
HIGH
IIS 6 WEBDAV Exploit
N/A
CWE
Product Name: IIS 6
Affected Version From: IIS 6
Affected Version To: IIS 6
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
IIS 6 WEBDAV Exploit
This exploit allows an attacker to gain access to a vulnerable IIS 6 server and execute arbitrary code. The exploit works by sending a specially crafted PROPFIND request to the server, which will then return a list of files and directories on the server. The attacker can then use this information to gain access to the server and execute arbitrary code.
Mitigation:
Ensure that all IIS 6 servers are patched and up to date.