6.8
CVSSv2

CVE-2010-2731

Published: 15/09/2010 Updated: 23/11/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled, allows remote malicious users to bypass intended access restrictions and execute ASP files via a crafted request, aka "Directory Authentication Bypass Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

MS10-065 - Directory Authentication Bypass Vulnerability Description: This vulnerability is because of using Alternate Data Stream to open a protected folder All of IIS authentication methods can be circumvented In this technique, we can add a “:$i30:$INDEX_ALLOCATION” to a directory name to bypass the authentication Download: gith ...