ID

VAR-200705-0069


CVE

CVE-2007-2815


TITLE

Microsoft IIS Web Server of webhits.dll Private in Web Directory access vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2007-003889

DESCRIPTION

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw. Microsoft IIS is prone to an authentication-bypass vulnerability due to its implementation of 'Hit-highlighting' functionality. Attackers can exploit this issue to access private files hosted on an IIS website. Successful exploits may allow attackers to gain access to potentially sensitive information. Other attacks are possible. NOTE: Presumably, accessing a Trusted Zone may allow attackers to execute commands; this has not been confirmed

Trust: 1.89

sources: NVD: CVE-2007-2815 // JVNDB: JVNDB-2007-003889 // BID: 24105

AFFECTED PRODUCTS

vendor:microsoftmodel:internet information servicesscope:eqversion:5.0

Trust: 1.6

vendor:microsoftmodel:iisscope:eqversion:5.0

Trust: 1.1

vendor:microsoftmodel:iisscope:eqversion:5.1

Trust: 0.3

vendor:microsoftmodel:iisscope:neversion:6.0

Trust: 0.3

sources: BID: 24105 // JVNDB: JVNDB-2007-003889 // CNNVD: CNNVD-200705-436 // NVD: CVE-2007-2815

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-2815
value: HIGH

Trust: 1.0

NVD: CVE-2007-2815
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200705-436
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2007-2815
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2007-003889 // CNNVD: CNNVD-200705-436 // NVD: CVE-2007-2815

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.8

sources: JVNDB: JVNDB-2007-003889 // NVD: CVE-2007-2815

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200705-436

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-200705-436

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-003889

PATCH

title:328832url:http://support.microsoft.com/kb/328832

Trust: 0.8

sources: JVNDB: JVNDB-2007-003889

EXTERNAL IDS

db:NVDid:CVE-2007-2815

Trust: 2.7

db:BIDid:24105

Trust: 1.9

db:SREASONid:2725

Trust: 1.6

db:OSVDBid:41091

Trust: 1.6

db:JVNDBid:JVNDB-2007-003889

Trust: 0.8

db:BUGTRAQid:20070522 [ISECAUDITORS SECURITY ADVISORIES] MICROSOFT IIS5 NTLM AND BASIC AUTHENTICATION BYPASS

Trust: 0.6

db:MSKBid:328832

Trust: 0.6

db:CNNVDid:CNNVD-200705-436

Trust: 0.6

sources: BID: 24105 // JVNDB: JVNDB-2007-003889 // CNNVD: CNNVD-200705-436 // NVD: CVE-2007-2815

REFERENCES

url:http://support.microsoft.com/kb/328832

Trust: 1.9

url:http://www.securityfocus.com/bid/24105

Trust: 1.6

url:http://securityreason.com/securityalert/2725

Trust: 1.6

url:http://osvdb.org/41091

Trust: 1.6

url:http://www.securityfocus.com/archive/1/469238/100/0/threaded

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-2815

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-2815

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/469238/100/0/threaded

Trust: 0.6

url:http://www.microsoft.com/windowsserver2003/iis/default.mspx

Trust: 0.3

url:http://www.microsoft.com/technet/security/prodtech/iis.mspx

Trust: 0.3

url:/archive/1/469238

Trust: 0.3

sources: BID: 24105 // JVNDB: JVNDB-2007-003889 // CNNVD: CNNVD-200705-436 // NVD: CVE-2007-2815

CREDITS

Jesus Olmos Gonzalez※ jolmos@isecauditors.com

Trust: 0.6

sources: CNNVD: CNNVD-200705-436

SOURCES

db:BIDid:24105
db:JVNDBid:JVNDB-2007-003889
db:CNNVDid:CNNVD-200705-436
db:NVDid:CVE-2007-2815

LAST UPDATE DATE

2025-04-10T23:09:46.198000+00:00


SOURCES UPDATE DATE

db:BIDid:24105date:2007-05-31T20:41:00
db:JVNDBid:JVNDB-2007-003889date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200705-436date:2007-05-23T00:00:00
db:NVDid:CVE-2007-2815date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:BIDid:24105date:2007-05-22T00:00:00
db:JVNDBid:JVNDB-2007-003889date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200705-436date:2007-05-22T00:00:00
db:NVDid:CVE-2007-2815date:2007-05-22T19:30:00