CVE-2009-1535
Published Jun 10, 2009
Last updated 4 years ago
Overview
- Description
- The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:internet_information_services:5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25100F8C-58A0-49D5-8247-8CCD099A734B" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:-:*", "vulnerable": false, "matchCriteriaId": "C5D2C681-EB06-4B72-BD34-47AEE35CC227" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:professional:*:-:*", "vulnerable": false, "matchCriteriaId": "81E8A3CB-9110-4D65-BCAE-261FF7135544" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:internet_information_services:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B4DF95D-B4B1-4FB6-9D27-A6D359EEACFA" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1D929AA2-EE0B-4AA1-805D-69BCCA11B77F" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:itanium:*", "vulnerable": false, "matchCriteriaId": "9F98AE07-3995-4501-9804-FEA5A87ADFAD" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:x64:*", "vulnerable": false, "matchCriteriaId": "A7371547-290D-4D0D-B98D-CA28B4D2E8B0" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*", "vulnerable": false, "matchCriteriaId": "C6109348-BC79-4ED3-8D41-EA546A540C79" } ], "operator": "OR" } ], "operator": "AND" } ]