HTTP: Microsoft IIS WebDAV Remote Authentication Bypass

This signature detects attempts to exploit a known vulnerability against Microsoft IIS WebDAV. Attackers can bypass access restrictions, gaining access to files or directories without providing authentication credentials.

Extended Description

Microsoft Internet Information Service (IIS) is prone to multiple authentication-bypass vulnerabilities because the application fails to properly enforce access restrictions on certain requests to password-protected WebDAV folders. An attacker can exploit these issues to gain unauthorized access to protected WebDAV resources, which may lead to other attacks. This issue affects IIS 5.0, 5.1, and 6.0.

Affected Products

Avaya messaging_application_server,Microsoft iis

References

BugTraq: 34993

CVE: CVE-2009-1535

Short Name
HTTP:IIS:WEBDAV:AUTH-BYPASS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Authentication Bypass CVE-2009-1535 IIS Microsoft Remote WebDAV bid:34993
Release Date
05/19/2009
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Avaya

Microsoft

CVSS Score

7.6

Found a potential security threat?