vendor:
Internet Information Server
by:
Kingcope
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: Internet Information Server
Affected Version From: IIS 6.0
Affected Version To: IIS 6.0
Patch Exists: NO
Related CWE:
CPE: a:microsoft:internet_information_server:6.0
Platforms Tested: Linux
2007
Lame Internet Information Server 6.0 Denial Of Service (nonpermanent)
When sending multiple parallel GET requests to an IIS 6.0 server requesting /AUX/.aspx, the server becomes unstable and non-responsive. This only happens to servers that respond with a runtime error (System.Web.HttpException) and take two or more seconds to respond to the /AUX/.aspx GET request.
Mitigation:
There is no specific mitigation mentioned in the text.