MS.IIS.WebHits.Authentication.Bypass

description-logoDescription

This indicates an attempt to exploit an authentication-bypass vulnerability in Microsoft IIS Web Server.
The vulnerability is in the "hit-highlighting" functionality in webhits.dll. By exploiting this vulnerability, remote attackers may be able to access private information from an IIS site.

affected-products-logoAffected Products

Microsoft IIS 5.0, 5.1.

Impact logoImpact

Information Disclosure: remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to Microsoft IIS version 6.0 or later.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)