NT Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Update Rollup 3 for Exchange Server 2010 Service Pack 2 (KB2685289)
· Microsoft outsources copyright enforcement to small Redmond company
· Microsoft to officially distribute products in Iraq
· Microsoft finally goes public with Windows Azure Active Directory details
· DSA 2480-2: request-tracker3.8 regression update
· Kernel/OpenSSL Updates for CentOS
· Fedora 17 released
· Chinese Windows 8 Release Preview (build 8400) leaked
· Daily Reviews Summary 05/29/12
· Microsoft Xbox 720 to feature in-game Skype integration

Upcoming News
· Buffalo CloudStor Pro 2TB NAS Review @ t-break
· News: Silverstone's Temjin TJ08-E Evolution enclosure
· Mushkin Redline PC3-12800 (994057) 16GB Quad Pack Memory Kit Review @ Hi Tech Legion
· G.Skill Trident X 2400MHz Review @ OCC
· SSD NEWS: OCZ Releases Agility 4 SSD at Record Low SSD Prices For a New Release
· A MEGATechNews Flash - MEGATech Reviews – Kingston?= USB 3.0 Media Reader and MobileLite G3 Card Readers
· Mad Riders (XBLA) Game Review @ HardwareHeaven.com
· Alienware M14x R2 Ivy Bridge Laptop Review @ HardwareHeaven.com
· [CentOS-announce] CESA-2012:0699 Moderate CentOS 6 openssl Update
· [CentOS-announce] CESA-2012:0699 Moderate CentOS 5 openssl Update

Windows Compatibility
· IObit Malware Fighter
· IObit SmartDefrag
· Realtek High Definition Audio for 2K/XP/03
· Advanced SystemCare with Antivirus 2012
· Samsung Drive Diagnostic Utility (Hutil)
· Google Chrome 18.0.1025.168 Final
· Skype
· Advanced SystemCare Free 5.3.0.245 Final
· IObit SmartDefrag v2 Beta 3.0
· Atheros Wireless AR5B91 Driver

New Forum Topics
· USB Not detected on any PC
by: AntNik45
on: 2012-05-09 18:37
0 replies, 0 views

· RESIDENT EVIL 2 for PC
by: elyp00
on: 2012-05-04 07:55
0 replies, 0 views

· Need to know if those graphic cards works well on Ubuntu
by: Dechiqtor
on: 2012-04-19 23:04
0 replies, 0 views

· Obtaining IE8
by: packman
on: 2012-04-14 19:46
0 replies, 0 views

· A few problems running Warcraft II Battle.net Edition on Vista
by: Lord Claremorris
on: 2012-04-08 16:15
0 replies, 0 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Windows XP
· Microsoft
· Updates
· Interviews
· Windows Server 2003
· General
· Windows Vista
· Webcasts
· Windows Server 2008
· Windows Home Server
· Windows 7
· Windows 8
· Windows Phone 7

What's New
Login to see an overview of all news stories since your last visit.

Affiliates

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

NT Compatible » News » April 2001 » WebDAV Service Provider Can Allow Scripts to Levy Requests as User

WebDAV Service Provider Can Allow Scripts to Levy Requests as User

Posted by Philipp Esselbach on: 04/19/2001 12:26 PM [ Print | 0 comment(s) ]

The Microsoft Data Access Component Internet Publishing Provider provides access to WebDAV resources over the Internet. By design, it should differentiate between requests made by a user and those made
by a script running in the userīs browser. However, because of an
implementation flaw, it handles all requests in the security context
of the user. As a result, if a user browsed to a web page or opened an HTML e-mail that contained script, that script could access web-based resources as the user.

The specific actions an attacker could take via this vulnerability
would depend on the Web-based resources available to the user, and
the userīs privileges on them. However, it is likely that at a minimum, the attacker could browse the userīs intranet, and potentially access web-based e-mail as well.

Read more






Bookmark and Share

« The Theory of Antialiasing · Iwill BIOS fixes 686B problems »

NT Compatible » News » April 2001 » WebDAV Service Provider Can Allow Scripts to Levy Requests as User
All products mentioned are registered trademarks or trademarks of their respective owners.
© 1998-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition