Description: The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms,
and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI,
as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder,
aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.
To Search:
File list (Check if you may need any files):
Filename | Size | Date |
---|
MS09-020 | 0 | 2018-02-17
|
MS09-020\MS09-020-KB970483-CVE-2009-1535-IIS6.zip | 205979 | 2017-08-01
|
MS09-020\README.md | 1452 | 2017-08-01
|
MS09-020\iis6.0.png | 60803 | 2017-08-01 |