Iis| execution involves procedures:
Win2K systems with dual-character processing + IIS
Describe:
Win2K IIS can execute commands remotely
With:
Because some double-byte Win2K systems handle certain special characters characters different from the English version, these special character attackers can bypass IIS directory audits
To remotely access any file on your computer or execute arbitrary commands:
Http://www.linux.org.cn/scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir+c:\
This vulnerability is caused by coding,%C0%AF and%c1%9c encoding is/and \, and may result in the same effect.
Affected Systems:
Systems that use two-character processing such as: CN
+ IIS 4/iis 5
Unaffected system:
Systems that use single character processing such as: Us,en
Solution:
Install Patch:
-Microsoft IIS 4.0:
http://www.microsoft.com/ntserver/nts/downloads/critical/q269862
-Microsoft IIS 5.0:
http://www.microsoft.com/windows2000/downloads/critical/q269862