vendor:
Microsoft IIS
by:
ka0x
7.5
CVSS
HIGH
Remote Authentication Bypass
Unknown
CWE
Product Name: Microsoft IIS
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:microsoft:iis:6.0
Platforms Tested:
Unknown
Microsoft IIS 6.0 WebDAV Remote Authentication Bypass Exploit
This exploit allows an attacker to bypass authentication in Microsoft IIS 6.0 WebDAV. It can be used to retrieve source code or upload files to the server. The exploit takes advantage of a vulnerability in the handling of certain HTTP requests.
Mitigation:
Apply the latest security patches for Microsoft IIS 6.0. Disable WebDAV if it is not needed.