Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.11161
Kategorie:CGI abuses
Titel:RDS / MDAC Vulnerability Content-Type overflow
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote DLL /msadc/msadcs.dll is accessible by anyone.
Several flaws have been found in it in the past, we recommend
you restrict access to MSADC only to trusted hosts.

Solution:
- Launch the Internet Services Manager
- Select your web server
- Right-click on MSADC and select 'Properties'
- Select the tab 'Directory Security'
- Click on the 'IP address and domain name restrictions'
option
- Make sure that by default, all computers are DENIED access
to this resource
- List the computers that should be allowed to use it

See also: MS advisory MS02-065
Risk factor: High

Querverweis: BugTraq ID: 6214
Common Vulnerability Exposure (CVE) ID: CVE-2002-1142
http://www.securityfocus.com/bid/6214
http://www.cert.org/advisories/CA-2002-33.html
CERT/CC vulnerability note: VU#542081
http://www.kb.cert.org/vuls/id/542081
http://www.foundstone.com/knowledge/randd-advisories-display.html?id=337
Microsoft Security Bulletin: MS02-065
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-065
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2730
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A294
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3573
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0082.html
XForce ISS Database: mdac-rds-client-bo(10669)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10669
XForce ISS Database: mdac-rds-server-bo(10659)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10659
CopyrightThis script is Copyright (C) 2002 Renaud Deraison

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.