OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[VulnWatch] Microsoft IIS 5.0 WebDAV remote buffer overflow

From: Chris Wysopal (weldvulnwatch.org)
Date: Mon Mar 17 2003 - 14:13:59 CST


Exploitation enables arbitrary code execution as LocalSystem by default.

Microsoft bulletin:
http://www.microsoft.com/technet/security/bulletin/MS03-007.asp

CERT Advisory:
http://www.cert.org/advisories/CA-2003-09.html

IIS alert:
http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029