Rapid7 Vulnerability & Exploit Database

Microsoft IIS 3.0/4.0 Upgrade BDIR.HTR Vulnerability

Back to Search

Microsoft IIS 3.0/4.0 Upgrade BDIR.HTR Vulnerability

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
11/01/2004
Created
07/25/2018
Added
11/01/2004
Modified
07/31/2012

Description

Microsoft Internet Information Server (IIS) 3.0 came with a series of remote administration scripts installed in /scripts/iisadmin off the web root directory. ism.dll is required for processing these scripts, and version 3.0 of IIS came with an ism.dll containing an authentication scheme to prevent unauthorized access. If an IIS 3.0 installation is upgraded to IIS 4.0 without removing these scripts, they can be accessed remotely without authentication due to changes in the authentication methods used by IIS 4.0. One of these scripts, bdir.htr, still functions under the IIS 4.0 server - and can be used by a remote attacker to obtain information about the server's directory structure. The script displays a directory listing of a directory specified as part of a request - but only directory names are displayed. Although privilege elevation cannot be accomplished directly by exploiting this script, the information about the server's directory structure thus obtained could potentially be used in mounting further attacks.

Solution(s)

  • http-iis-0033

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;