Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86f6-f7gx-x5qm

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.

EPSS

Процентиль: 99%
0.85872
Высокий

Связанные уязвимости

nvd
больше 18 лет назад

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.

EPSS

Процентиль: 99%
0.85872
Высокий