|
[Japanese]
|
JVNDB-2008-000076
|
sISAPILocation vulnerability bypasses HTTP header rewrite function
|
sISAPILocation, an ISAPI (Internet Server Application Program Interface) filter, contains a vulnerability that allows the HTTP header rewrite function to be bypassed.
sISAPILocation, developed by an individual developer, is an ISAPI filter for IIS (Internet Information Services). sISAPILocation contains a vulnerability that allows the HTTP header rewrite function to be bypassed.
|
Base Metrics:
4.3 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
Tomoki Sanaki
- sISAPILocation Ver1.0.2.1 and earlier
|
When sISAPILocation is used to configure settings, such as to specify character encoding or to set the secure flag for cookies, such settings could be bypassed.
|
[Update the Software]
Update to the latest version according to the information provided by the developer.
[Workarounds]
Do not use the Keep-Alive feature on IIS until update is completed.
|
Tomoki Sanaki
- sanaki's Freesoft : free100 (Japanese)
|
- JVN : JVN#67060882
- National Vulnerability Database (NVD) : CVE-2008-6298
- Common Vulnerabilities and Exposures (CVE) : CVE-2008-6298
- Secunia Advisory : SA32581
- SecurityFocus : 32247
- VUPEN Security : VUPEN/ADV-2008-3105
- Common Weakness Enumeration (CWE) : Insufficient Input Validation (CWE-20) [IPA Evaluation]
- JVN iPedia (Japanese) : JVNDB-2008-000076
|
[2008/11/10]
Web page published
|
|
| 2008/11/06 |
| 2008/11/10 |
| 2008/11/10 |
|