Exploit Microsoft IIS 4.0 - UNC Mapped Virtual Host

Exploiter

Хакер
34,599
0
18 Дек 2022
EDB-ID
19824
Проверка EDB
  1. Пройдено
Автор
ADAM COYNE
Тип уязвимости
REMOTE
Платформа
MULTIPLE
CVE
cve-2000-0246
Дата публикации
2000-03-30
Microsoft IIS 4.0 - UNC Mapped Virtual Host
Код:
MS Commercial Internet System 2.0/2.5,IIS 4.0,Proxy Server 2.0,Site Server Commerce Edition 3.0 UNC Mapped Virtual Host Vulnerability

source: https://www.securityfocus.com/bid/1081/info

If a virtual host root is mapped to a UNC share, a backward slash "\" appended to an ASP or HTR extension in a URL request to that virtual host will cause Microsoft Internet Information Server to transmit full source code of the file back to a remote user. Files located on the local drive where IIS is installed is not affected by this vulnerability. 

http://target/file.asp\
 
Источник
www.exploit-db.com

Похожие темы