PT-2009-6565 · Microsoft · Internet Information Services

Published

2009-12-29

·

Updated

2020-11-23

·

CVE-2009-4444

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) versions 5.x through 6.x
Description The issue allows remote attackers to bypass intended extension restrictions of third-party upload applications. This is achieved by using a filename with a first extension such as .asp, .cer, or .asa, followed by a semicolon and a safe extension. For example, using asp.dll to handle a .asp;.jpg file.
Recommendations For Microsoft Internet Information Services (IIS) versions 5.x through 6.x, consider configuring the server to handle file extensions more securely, such as by ignoring any characters after a semicolon in filenames. As a temporary workaround, restrict the use of sensitive extensions like .asp, .cer, or .asa in upload applications until a more robust solution is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-4444

Affected Products

Internet Information Services