MEDIUM
Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a filename containing an initial extension followed by a : (colon) and a safe extension, as demonstrated by an upload of a .asp:.jpg file that results in creation of an empty .asp file, related to support for the NTFS Alternate Data Streams (ADS) filename syntax
Published Dec 29, 2009
6.0
MEDIUMCVSS 2.0
EPSS 12.76%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.