The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.
References
Configurations
Information
Published : 2007-05-22 12:30
Updated : 2018-10-16 09:45
NVD link : CVE-2007-2815
Mitre link : CVE-2007-2815
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
microsoft
- internet_information_services