First published: Tue Jul 18 2006(Updated: )
Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Security and Acceleration Server | =2004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3652 has been classified as a medium severity vulnerability.
To mitigate CVE-2006-3652, ensure that file extension filters are properly configured and consider using updated software versions.
CVE-2006-3652 allows remote attackers to bypass file extension filters in Microsoft ISA Server 2004.
CVE-2006-3652 specifically affects Microsoft ISA Server 2004 and might not be exploitable on other versions.
The primary component affected by CVE-2006-3652 is the file extension filtering mechanism in Microsoft ISA Server 2004.