Vulnerabilities > CVE-2006-0026 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Microsoft IIS ASP Stack Overflow Exploit (MS06-034). CVE-2006-0026. Local exploit for windows platform |
id | EDB-ID:2056 |
last seen | 2016-01-31 |
modified | 2006-07-21 |
published | 2006-07-21 |
reporter | cocoruder |
source | https://www.exploit-db.com/download/2056/ |
title | Microsoft IIS ASP - Stack Overflow Exploit MS06-034 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-034.NASL |
description | The remote host is running a version of Windows and IIS that is vulnerable to a flaw that could allow an attacker who has the privileges to upload arbitrary ASP scripts to it to execute arbitrary code. Specifically, the remote version of IIS is vulnerable to a flaw when parsing specially crafted ASP files. By uploading a malicious ASP file on the remote host, an attacker may be able to take the complete control of the remote system. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22028 |
published | 2006-07-11 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22028 |
title | MS06-034: Vulnerability in Microsoft IIS using ASP Could Allow Remote Code Execution (917537) |
code |
|
Oval
accepted | 2008-02-25T04:00:08.981-05:00 | ||||||||||||||||||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||||||||||||||||||
description | Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). | ||||||||||||||||||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:435 | ||||||||||||||||||||||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||||||||||||||||||||||
submitted | 2006-07-25T12:05:33 | ||||||||||||||||||||||||||||||||||||||||||||||||
title | Internet Information Services using Malformed Active Server Pages Vulnerability | ||||||||||||||||||||||||||||||||||||||||||||||||
version | 37 |
References
- http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html
- http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html
- http://secunia.com/advisories/21006
- http://secunia.com/advisories/21006
- http://securitytracker.com/id?1016466
- http://securitytracker.com/id?1016466
- http://www.kb.cert.org/vuls/id/395588
- http://www.kb.cert.org/vuls/id/395588
- http://www.osvdb.org/27152
- http://www.osvdb.org/27152
- http://www.securityfocus.com/bid/18858
- http://www.securityfocus.com/bid/18858
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html
- http://www.vupen.com/english/advisories/2006/2752
- http://www.vupen.com/english/advisories/2006/2752
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-034
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-034
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26796
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26796
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A435
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A435