Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft IIS Administrative Pages Cross Site Scripting Vulnerabilities

Microsoft IIS is prone to cross site scripting attacks. The vulnerability is a result of improper sanitization of user-supplied input by IIS. Several web pages, provided by IIS for administrative purposes do not adequately sanitize user-supplied input. Any malicious HTML code that may be included in the URI will be executed.

This vulnerability could allow an attacker to execute script code in the 'Intranet' security zone.

This vulnerability was originally described in BugTraq ID 6068. It is now being assigned its own BugTraq ID.







 

Privacy Statement
Copyright 2008, SecurityFocus