IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Se…
Info
Summary
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://www.osvdb.org/436
- http://www.securityfocus.com/bid/1806
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-078
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5377
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A44
- http://www.osvdb.org/436
- http://www.securityfocus.com/bid/1806
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-078
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5377
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A44
Timeline
- nvd_ingest NVD