vendor:
IIS
by:
Soroush Dalili
7,5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: IIS
Affected Version From: IIS 1.0, Windows NT 3.51
Affected Version To: IIS 7.5, Windows 2008 (classic pipeline mode)
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:iis
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows NT 3.51, Windows NT 4.0, Windows 2000, Windows XP Professional, Windows XP Media Center Edition, Windows Server 2003, Windows XP Professional x64 Edition, Windows Server 2008, Windows Vista, Windows 7, Windows 2008
2012
IIS Short File/Folder Name Disclosure
Vulnerability Research Team discovered a vulnerability in Microsoft IIS. The vulnerability is caused by a tilde character "~" in a Get request, which could allow remote attackers to diclose File and Folder names.
Mitigation:
Using a configured WAF may be usefull (discarding web requests including the tilde "~" character).