Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9gf-r7p8-qf28

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.

EPSS

Процентиль: 100%
0.92339
Критический

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 16 лет назад

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.

EPSS

Процентиль: 100%
0.92339
Критический

Дефекты

CWE-287