First published: Fri Dec 15 2006(Updated: )
Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Server | <=5.0 | |
Microsoft Internet Information Server | =3.0 | |
Microsoft Internet Information Server | =4.0-alpha | |
Microsoft Internet Information Server | =4.0 | |
Microsoft Internet Information Services | =1.0 | |
Microsoft Internet Information Services | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.