vendor:
Microsoft IIS
by:
Indigo
7.5
CVSS
HIGH
Code Execution
94
CWE
Product Name: Microsoft IIS
Affected Version From: Microsoft IIS 4.0
Affected Version To: Microsoft IIS 5.0
Patch Exists: NO
Related CWE:
CPE: a:microsoft:iis:4.0, cpe:/a:microsoft:iis:5.0
Platforms Tested: Linux, Win32
2001
Microsoft IIS Server Side Include exploit
A vulnerability exists in Microsoft IIS 4.0 and 5.0 that could allow a user with permission to write content to the IIS server to run any code in Local System context. This exploit generates a file called ssi.shtml and requires write access to the web root of the target web server. By accessing the file using a web browser, a SYSTEM shell will appear in the Netcat session.
Mitigation:
Apply patches and updates provided by Microsoft. Limit write access to the web root of the IIS server.