Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-1135

EPSS 39.38% · P97
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-1135

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft ISA Server绕过Radius OTP认证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ISA Server是微软产品家族之一,可以提供企业防火墙和高性能的Web缓存 。 如果对ISA Server 2006配置了使用RADIUS OTP的基于表单认证(FBA),则当该服务器从用户代理接收到请求要求回退到HTTP-Basic认证时,ISA就无法正确地认证该请求。如果配置了KCD,ISA会继续对已发布的服务器使用KCD进行认证。对于知道管理员账号用户名的攻击者,成功利用这个漏洞可以完全控制依赖ISA Server 2006 Web发布规则进行认证的系统。攻击者随后可安装程序;查看、更改或删除数
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-1135

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-1135

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-07-15 · 9 CVEs total

CVE-2009-0231Microsoft Windows EOT字体引擎堆溢出和整数溢出漏洞
CVE-2009-0232Microsoft Windows EOT字体引擎堆溢出和整数溢出漏洞
CVE-2009-0566Microsoft Office Publisher指针引用代码执行漏洞
CVE-2009-1136Microsoft Office Spreadsheet ActiveX控件内存破坏漏洞
CVE-2009-1538Microsoft DirectX DirectShow指针验证远程代码执行漏洞
CVE-2009-1539Microsoft DirectX长度记录解析内存破坏漏洞
CVE-2009-1542Microsoft Virtual PC和Virtual Server本地权限提升漏洞
CVE-2009-2477Mozilla Firefox Tracemonkey组件远程代码执行漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-1135

No comments yet


Leave a comment