| Vulnerability Name: | CVE-2009-1122 (CCN-50573) | ||||||||
| Assigned: | 2009-05-15 | ||||||||
| Published: | 2009-05-15 | ||||||||
| Updated: | 2020-11-23 | ||||||||
| Summary: | The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
6.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-287 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2009-1122 Source: MITRE Type: CNA CVE-2009-1535 Source: CCN Type: SA35109 Microsoft Internet Information Services WebDAV Request Directory Security Bypass Source: CCN Type: SECTRACK ID: 1022358 Microsoft Internet Information Services WebDAV Bug Lets Remote Users Bypass Authentication Source: CCN Type: ASA-2009-215 MS09-020 Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483) Source: VIM Type: Third Party Advisory 20090616 IIS WebDav Vulnerability CVE ID Source: CCN Type: Microsoft IIS Web site The Official Microsoft IIS Site Source: CCN Type: US-CERT VU#787932 Microsoft IIS WebDAV Remote Authentication Bypass Source: CCN Type: Microsoft Security Advisory (971492) Vulnerability in Internet Information Services Could Allow Elevation of Privilege Source: CCN Type: Microsoft Security Bulletin MS09-020 Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483) Source: CCN Type: BID-34993 Microsoft IIS Unicode Requests to WebDAV Multiple Authentication Bypass Vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 35232 Source: CCN Type: BID-35232 Microsoft IIS 5.0 WebDAV Authentication Bypass Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1022358 Source: CERT Type: Third Party Advisory, US Government Resource TA09-160A Source: VUPEN Type: Third Party Advisory ADV-2009-1539 Source: MS Type: Patch, Vendor Advisory MS09-020 Source: XF Type: UNKNOWN iis-webdav-security-bypass(50573) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:5861 Source: CCN Type: Rapid7 Vulnerability and Exploit Database [05-30-2018] MS09-020 IIS6 WebDAV Unicode Auth Bypass Directory Scanner | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||