| Vulnerability Name: | CVE-2006-6578 (CCN-31011) | ||||||||
| Assigned: | 2006-12-12 | ||||||||
| Published: | 2006-12-12 | ||||||||
| Updated: | 2020-12-08 | ||||||||
| Summary: | Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com when it is in a web directory with certain permissions. | ||||||||
| CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Tue Dec 12 2006 - 20:02:56 CST ASP Cmd Shell On IIS 5.1 Source: MITRE Type: CNA CVE-2006-6578 Source: SREASON Type: Exploit, Third Party Advisory 2036 Source: CCN Type: OSVDB ID: 35950 Microsoft IIS IUSR_Machine Account Arbitrary Non-EXE Command Execution Source: BUGTRAQ Type: Exploit, Third Party Advisory, VDB Entry 20061213 ASP Cmd Shell On IIS 5.1 Source: XF Type: UNKNOWN iis-iusrmachine-command-execution(31011) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||