NVD
- Id
- 48808
- Name
- CVE-2009-1535
- Description
- The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.
- Reject
- CVSS Version
- 2
- CVSS Score
- 7.6
- Severity
- High
- CVSS Base Score
- 7.6
- CVSS Impact Subscore
- 10
- CVSS Exploit Subscore
- 4.9
- CVSS Vector
- (AV:N/AC:H/Au:N/C:C/I:C/A:C)
- Pub Date
- 2017-01-07
- Published
- 2009-06-10
- Modified Date
- 2010-08-21
- Seq
- 2009-1535