PT-2010-4250 · Microsoft · Windows Xp+1

Publicado

2010-09-15

·

Atualizado

2020-11-23

·

CVE-2010-2731

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) version 5.1 on Windows XP SP3
Description The issue allows remote attackers to bypass intended access restrictions and execute ASP files via a crafted request when directory-based Basic Authentication is enabled.
Recommendations For Microsoft Internet Information Services (IIS) version 5.1 on Windows XP SP3, consider disabling directory-based Basic Authentication as a temporary workaround until a patch is available. Restrict access to sensitive directories and ASP files to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2731

Produtos afetados

Internet Information Services
Windows Xp