|
Minimum DAT
4164 (2001-10-03)
Updated DAT
4754 (2006-05-03)
|
Minimum Engine
5.1.00
File Length
various
|
Description Added
2003-04-02
Description Modified
2003-04-02
|
Exploit-IIS is a perl tool that verify web servers vulnerability against the "/" encoding.
It tries to access the remote web server root by using encoded "/" (the otherwise called "dot dot root vulnerability"). If successful it lists all accessible folders and vulnerable executables such as cmd.exe. It support ssl (https) and provides some upload features.
Note: Although this program is specifically designed as a security test tool it could be used by a malicious attacker to compromise remote web servers.
There are know variants that behave slightly differently.
This tool tests remote web server "dot dot root" vulnerability.