Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.100952
Categoría:FTP
Título:Microsoft IIS FTPd NLST stack overflow
Resumen:Microsoft IIS FTPd NLST stack overflow;; The Microsoft IIS FTPd service may be vulnerable to a stack overflow via the NLST command. On Microsoft IIS 5.x this vulnerability; can be used to gain remote SYSTEM level access, whilst on IIS 6.x it has been reported to result in a denial of service. Whilst it; can be triggered by authenticated users with write access to the FTP server, this check determines whether anonymous users have the; write access necessary to trigger it without authentication.
Descripción:Summary:
Microsoft IIS FTPd NLST stack overflow

The Microsoft IIS FTPd service may be vulnerable to a stack overflow via the NLST command. On Microsoft IIS 5.x this vulnerability
can be used to gain remote SYSTEM level access, whilst on IIS 6.x it has been reported to result in a denial of service. Whilst it
can be triggered by authenticated users with write access to the FTP server, this check determines whether anonymous users have the
write access necessary to trigger it without authentication.

Solution:
We are not aware of a vendor approved solution at the current time.

On the following platforms, we recommend you mitigate in the described manner:

Microsoft IIS 5.x

Microsoft IIS 6.x

We recommend you mitigate in the following manner:

Filter inbound traffic to 21/tcp to only known management hosts
Consider removing directories writable by 'anonymous'

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-3023
BugTraq ID: 36189
http://www.securityfocus.com/bid/36189
Cert/CC Advisory: TA09-286A
http://www.us-cert.gov/cas/techalerts/TA09-286A.html
CERT/CC vulnerability note: VU#276653
http://www.kb.cert.org/vuls/id/276653
http://www.exploit-db.com/exploits/9541
http://www.exploit-db.com/exploits/9559
Microsoft Security Bulletin: MS09-053
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-053
Microsoft Knowledge Base article: 975191
http://support.microsoft.com/default.aspx?scid=kb;[LN];Q975191
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6080
http://www.vupen.com/english/advisories/2009/2481
CopyrightCopyright (C) 2009 Tim Brown

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.