CVE-2006-3652: High severity Microsoft ISA Server vulnerability
Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3652?
CVE-2006-3652 has been classified as a medium severity vulnerability.
How do I fix CVE-2006-3652?
To mitigate CVE-2006-3652, ensure that file extension filters are properly configured and consider using updated software versions.
What type of attack does CVE-2006-3652 enable?
CVE-2006-3652 allows remote attackers to bypass file extension filters in Microsoft ISA Server 2004.
Is CVE-2006-3652 exploitable on all versions of ISA Server?
CVE-2006-3652 specifically affects Microsoft ISA Server 2004 and might not be exploitable on other versions.
What is the primary component affected by CVE-2006-3652?
The primary component affected by CVE-2006-3652 is the file extension filtering mechanism in Microsoft ISA Server 2004.