vendor:
Personal Web Server
by:
SecurityFocus
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: Personal Web Server
Affected Version From: Personal Web Server 1.0
Affected Version To: Personal Web Server 3.0
Patch Exists: YES
Related CWE: CVE-2001-0333
CPE: a:microsoft:personal_web_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2001
IIS CGI Filename Decoding Vulnerability
When IIS receives a CGI filename request, it automatically performs two actions before completing the request. A flaw in IIS involves a third undocumented action: Typically, IIS decodes only the CGI parameter at this point, yet the previously decoded CGI filename is mistakenly decoded twice. If a malformed filename is submitted and circumvents the initial security check, the undocumented procedure will decode the malformed request, possibly allowing the execution of arbitrary commands.
Mitigation:
Ensure that all CGI requests are properly sanitized and validated before being processed.