HTTP: IIS Perl Browse 0x0a Attempt

This signature detects attacks against Microsoft IIS with Perl. Attacker can execute arbitrary commands on the system.

Extended Description

ActivePerl is an implementation of the Perl scripting language for Microsoft Windows systems developed by Activestate. ActivePerl allows for high-performance integration with IIS using a DLL called 'perlIIS.dll' to handle a '.plx' ISAPI extension. perlIIS.dll contains a remotely exploitable buffer overflow vulnerability in handling of the URL string. It is due to an unbounded string copy operation. All versions of ActivePerl prior to build 630 of ActivePerl 5.6.1 are believed to be vulnerable. This vulnerability requires that the option "Check that file exists" be disabled. This option is enabled by default. Exploitation of this vulnerability may allow for remote attackers to gain access to the target server.

Affected Products

Activestate activeperl

References

BugTraq: 3526

CVE: CVE-2001-0815

Short Name
HTTP:IIS:PERL-0A-ATTEMPT
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
0x0a Attempt Browse CVE-2001-0815 IIS Perl bid:3526
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Activestate

CVSS Score

7.5

Found a potential security threat?