A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."
Link | Tags |
---|---|
http://www.ciac.org/ciac/bulletins/n-011.shtml | third party advisory government resource |
http://www.securityfocus.com/bid/6068 | vdb entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062 | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A931 | vdb entry signature |
http://www.securityfocus.com/bid/6071 | vdb entry |
http://www.iss.net/security_center/static/10504.php | vdb entry patch vendor advisory |