PT-2009-6565 · Microsoft · Internet Information Services

Publicado

2009-12-29

·

Atualizado

2020-11-23

·

CVE-2009-4444

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) versions 5.x through 6.x
Description The issue allows remote attackers to bypass intended extension restrictions of third-party upload applications. This is achieved by using a filename with a first extension such as .asp, .cer, or .asa, followed by a semicolon and a safe extension. For example, using asp.dll to handle a .asp;.jpg file.
Recommendations For Microsoft Internet Information Services (IIS) versions 5.x through 6.x, consider configuring the server to handle file extensions more securely, such as by ignoring any characters after a semicolon in filenames. As a temporary workaround, restrict the use of sensitive extensions like .asp, .cer, or .asa in upload applications until a more robust solution is implemented.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-4444

Produtos afetados

Internet Information Services