|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Microsoft Internet Information Server (IIS) contain a flaw that allows a remote attacker to access any file or folder on the Web Server with "anonymous" access. The issue is due to IIS failing to handle Unicode characters in URI requests. By replacing slashes and backslashes with their Unicode equivilent, an attacker can bypass the sanity checks present in IIS that would normally filter and deny such requests.
|
|
Classification |
Unknown or Incomplete
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.
|
|
Products |
|
IIS
 |
4.0 |
5.0 |
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|