PT-2009-6565 · Microsoft · Internet Information Services
Published
2009-12-29
·
Updated
2020-11-23
·
CVE-2009-4444
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Information Services (IIS) versions 5.x through 6.x
Description
The issue allows remote attackers to bypass intended extension restrictions of third-party upload applications. This is achieved by using a filename with a first extension such as
.asp, .cer, or .asa, followed by a semicolon and a safe extension. For example, using asp.dll to handle a .asp;.jpg file.Recommendations
For Microsoft Internet Information Services (IIS) versions 5.x through 6.x, consider configuring the server to handle file extensions more securely, such as by ignoring any characters after a semicolon in filenames. As a temporary workaround, restrict the use of sensitive extensions like
.asp, .cer, or .asa in upload applications until a more robust solution is implemented.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Information Services