|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Microsoft IIS contains a flaw that allows a remote attacker to create arbitrary files or a denial of service on a remote server. The issue is due to the "newdsn.exe" CGI application not sanitizing arguments provided. If an attacker is able to create a file on the system, it can be leveraged for additional privileges.
|
|
Classification |
Unknown or Incomplete
|
|
Solution |
Remove newdsn.exe from the /scripts/tools web directory. This is normally mapped to C:InetPubScriptsTools but may be found in a different location depending on your installation.
|
|
Products |
|
IIS
 |
2.0 |
3.0 |
|
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|