Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Web Servers >> IIS Remote Command Execution


Vulnerability Assessment Details

IIS Remote Command Execution

Vulnerability Assessment Summary
Acertains if arbitrary commands can be executed

Detailed Explanation for this Vulnerability Assessment

Summary :

Arbitary commands can be executed on the remote web server

Description :

When IIS receives a user request to run a script, it renders
the request in a decoded canonical form, then performs
security checks on the decoded request. A vulnerability
results because a second, superfluous decoding pass is
performed after the initial security checks are completed.
Thus, a specially crafted request could permit a possible hacker to
execute arbitrary commands on the IIS Server.


Solution:

http://www.microsoft.com/technet/security/bulletin/ms01-026.mspx

Network Security Threat Level:

High / CVSS Base Score : 7
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)

Networks Security ID: 2708, 3193

Vulnerability Assessment Copyright: This script is Copyright (C) 2001 Matt Moore / H D Moore

Cables, Connectors


***NEW*** BCM RX67Q Gaming Motherboard | Intel Q67 2nd/3rd Gen. | LGA1155 | DDR3 picture

***NEW*** BCM RX67Q Gaming Motherboard | Intel Q67 2nd/3rd Gen. | LGA1155 | DDR3

$29.77



ASUS H110M-R Motherboard Intel 6th/7th Gen LGA1151 DDR4 Micro-ATX i/o shield picture

ASUS H110M-R Motherboard Intel 6th/7th Gen LGA1151 DDR4 Micro-ATX i/o shield

$42.00



Gigabyte Z370P D3 ATX Z370 LGA1151 Motherboard (Support Intel 6/7th 8th 9th) picture

Gigabyte Z370P D3 ATX Z370 LGA1151 Motherboard (Support Intel 6/7th 8th 9th)

$59.99



ASUS Prime Q270M-C LGA1151 DP HDMI VGA SATA 6GB/s USB 3.0 MicroATX Motherboard picture

ASUS Prime Q270M-C LGA1151 DP HDMI VGA SATA 6GB/s USB 3.0 MicroATX Motherboard

$37.99



ASUS Prime Z390-A LGA 1151 Intel Z390 SATA USB 3.1 ATX Motherboard NO I/O picture

ASUS Prime Z390-A LGA 1151 Intel Z390 SATA USB 3.1 ATX Motherboard NO I/O

$99.00



Asus H81M-C Intel LGA1150 DDR3 Desktop Motherboard MicroATX Socket H3; Works picture

Asus H81M-C Intel LGA1150 DDR3 Desktop Motherboard MicroATX Socket H3; Works

$29.99



Asrock Z390 Phantom Gaming 4S/AC Wifi 8th/9th Gen Intel 1151 Motherboard Bulk picture

Asrock Z390 Phantom Gaming 4S/AC Wifi 8th/9th Gen Intel 1151 Motherboard Bulk

$47.41



Gigabyte GA-B75M-HD3 Intel LGA1155 DDR3 Desktop Motherboard MicroATX USB 3.0  picture

Gigabyte GA-B75M-HD3 Intel LGA1155 DDR3 Desktop Motherboard MicroATX USB 3.0

$26.99



ASUS Prime B560m-a LGA 1200 Intel B560 SATA 6gb/s Micro ATX Intel Motherboard picture

ASUS Prime B560m-a LGA 1200 Intel B560 SATA 6gb/s Micro ATX Intel Motherboard

$34.19



As-is ASRock Z690 EXTREME WiFi 6E LGA 1700 Intel Z690 SATA 6Gb/s DDR4 ATX Intel picture

As-is ASRock Z690 EXTREME WiFi 6E LGA 1700 Intel Z690 SATA 6Gb/s DDR4 ATX Intel

$74.95



Discussions

No Discussions have been posted on this vulnerability.