about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Microsoft IIS 4.0/5.0 Session ID Cookie Disclosure Vulnerability


Title Microsoft IIS 4.0/5.0 Session ID Cookie Disclosure Vulnerability
Published 2000-10-23-12:00AM
Updated 2000-10-23-12:00AM
Class Design Error
CVE   CVE-2000-0970
Remote  No
Local  Yes
Credit  Discovered by ACROS Security <security@acros.si> and C. Conrad Cady and publicized in a Microsoft Security Bulletin (MS00-080) on October 23, 2000.
Vulnerable  Microsoft IIS 5.0
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Server
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Server SP2
Microsoft IIS 4.0
Cisco Building Broadband Service Manager 5.0
Cisco Call Manager 1.0
Cisco Call Manager 2.0
Cisco Call Manager 3.0
Cisco ICS 7750
Cisco IP/VC 3540 Video Rate Matching Module
Cisco Unity Server 2.0
Cisco Unity Server 2.2
Cisco Unity Server 2.3
Cisco Unity Server 2.4
Cisco uOne 1.0
Cisco uOne 2.0
Cisco uOne 3.0
Cisco uOne 4.0
Microsoft BackOffice 4.0
Microsoft BackOffice 4.5
Microsoft Windows NT 4.0 Option Pack
Not Vulnerable  
Code   Mitja Kolsek <mitja.kolsek@acros.si> goes through scenarios in his advisory (see 'Credit' tab) describing how a user could be misled to open a connection to a malicious website and provide a Session ID Cookie.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 15:08:45 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Teen caugh viewscreen ketrenakea homemadevi autoclose. SPOOF sexy vedio www.Xxxsex www.taobao apach 1.3. www.9970.o SunOS WWW.XXLX.C FTP port 2 scgyzs.com wwwthrisha phpBB por phpBB port vsftpd 2.0 Video Avat www.tamila t352t Intel& myanmarsex iranxiran SEXY PHOTO viduosex //plugins/ www.tamila /search/ex www.slazy www.trisha sexsmoves www.e-sush www.xxjc.c SEXY PHOTO lo436l maxcpm.inf Photo sexy ip hotmail sex5i.com Candlelanu tamil actr maxcpm.inf ff passwor Crack Data IPB 1.3.1 nuts girl fuck Tyra banks