Skip to main content

Microsoft Internet Information Services (IIS) Two Information Disclosure Vulnerabilities

Last Update Date: 14 Nov 2012 17:21 Release Date: 14 Nov 2012 4074 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers
  1. Password Disclosure Vulnerability
    An information disclosure vulnerability exists when Microsoft Internet Information Services (IIS) fails to properly protect log files.
  2. FTP Command Injection Vulnerabiliy
    An information disclosure vulnerability exists in the way that Microsoft Internet Information Services (IIS) FTP Service negotiates encrypted communications channels.

Impact

  • Information Disclosure

System / Technologies affected

  • Microsoft Internet Information Services (IIS) 7.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link