IIS WebDAV DoS v1.12

Vulnerability exploited: CAN-2003-0226 - BID-7735

Category: Denial of Service/Remote

This module causes a Denial of Service in Microsoft Internet Information Services using an overly long WebDAV request.
This module exploits a denial of service vulnerability that results because IIS 5.0 and 5.1 do not correctly handle an error condition when an overly long WebDAV request is passed to them.

Supported Systems:
    Windows 2000 Professional - sp3 (i386)
    Windows 2000 Server - sp2 (i386)
    Windows 2000 Server - sp3 (i386)
    Windows 2000 Advanced Server - sp2 (i386)
    Windows 2000 Advanced Server - sp3 (i386)
    Windows XP Professional - sp0 (i386)
    Windows XP Professional - sp0 (i386)
    Windows XP Home Edition - sp0 (i386)
    Windows XP Home Edition - sp1 (i386)
    Microsoft IIS 5.0 Windows 2000 Professional SP3
    Microsoft IIS 5.0 Windows 2000 Server SP2
    Microsoft IIS 5.0 Windows 2000 Server SP3
    Microsoft IIS 5.0 Windows 2000 Advanced Server SP2
    Microsoft IIS 5.0 Windows 2000 Advanced Server SP3
    Microsoft IIS 5.1 Windows XP Professional SP0
    Microsoft IIS 5.1 Windows XP Professional SP1
    Microsoft IIS 5.1 Windows XP Home SP0
    Microsoft IIS 5.1 Windows XP Home SP1


This module is included in the latest version of CORE IMPACT, the first automated comprehensive penetration testing product for accurately identifying information security risks. Click here to learn more about the product.