Description
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
Affected products
- microsoft / commercial_internet_system2.0 – 2.0
- microsoft / commercial_internet_system2.5 – 2.5
- microsoft / internet_information_server4.0 – 4.0
- microsoft / internet_information_services5.0 – 5.0
- microsoft / proxy_server2.0 – 2.0
- microsoft / site_server3.0 – 3.0
- microsoft / site_server_commerce3.0 – 3.0
Exploits & proofs of concept
- exploit-dbMicrosoft IIS 4.0 - UNC Mapped Virtual Hostby Adam Coyne
Updated 10m ago · 8 sources