Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Microsoft IIS 0Day Vulnerability

Go down

Microsoft IIS 0Day Vulnerability Empty Microsoft IIS 0Day Vulnerability

Post  andry Tue Nov 02, 2010 1:06 am

Microsoft IIS 0Day Vulnerability in Parsing Files (semiā€colon bug)

A vulnerability has been identified in Microsoft Internet Information Services (IIS) where the server in incorrectly handling files with multiple extensions separated by the ";" character such as "malicious.asp;.jpg" as an ASP file. This could allow attackers to upload malicious executables on a vulnerable web server, bypassing file extension protections and restrictions. This vulnerability does not work with ASP.Net.

Pending an IIS security patch, some workaround are available here.

Source:http://isc.sans.org

See also: Microsoft IIS vuln leaves users open to remote attack
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum