HTTP: Internet Information Services (IIS) Authentication Bypass

This signature detects attempts to exploit a known vulnerability against Microsoft IIS. Attackers can bypass access restrictions, gaining access to files or directories without providing authentication credentials.

Extended Description

Microsoft Internet Information Services (IIS) is prone to an authentication-bypass vulnerability because it fails to properly enforce access restrictions on certain requests to a site that requires authentication. An attacker can exploit this issue to gain unauthorized access to protected resources, which may lead to other attacks. This issue affects IIS 5.0.

Affected Products

Avaya messaging_application_server,Microsoft iis

References

BugTraq: 35232

CVE: CVE-2009-1122

Short Name
HTTP:IIS:IIS-AUTH-BYPASS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
(IIS) Authentication Bypass CVE-2009-1122 Information Internet Services bid:35232
Release Date
06/09/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3725
False Positive
Unknown
Vendors

Avaya

Microsoft

CVSS Score

7.6

Found a potential security threat?