# N/A
## 漏洞概述
ScStoragePathFromUrl函数在Internet Information Services (IIS) 6.0的WebDAV服务中存在缓冲区溢出漏洞,攻击者可以通过包含超长头部信息(以"If: `<http://"开头的`PROPFIND`请求来执行任意代码。
## 影响版本
- Microsoft Windows Server 2003 R2 (IIS 6.0)
## 漏洞细节
此漏洞存在于WebDAV服务的ScStoragePathFromUrl函数中。攻击者可以通过构造一个`PROPFIND`请求,其中头部信息包含一个超长字符串(以`If: `<http://`开头),触发缓冲区溢出,导致远程代码执行。
## 影响
远程攻击者可以利用此漏洞执行任意代码,导致系统被完全控制。此漏洞曾在2016年7月或8月被利用。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | An exploit for Microsoft IIS 6.0 CVE-2017-7269 | https://github.com/eliuha/webdav_exploit | POC详情 |
| 2 | CVE-2017-7269 回显PoC ,用于远程漏洞检测.. | https://github.com/lcatro/CVE-2017-7269-Echo-PoC | POC详情 |
| 3 | exec 8 bytes command | https://github.com/caicai1355/CVE-2017-7269-exploit | POC详情 |
| 4 | Poc for iis6.0 | https://github.com/M1a0rz/CVE-2017-7269 | POC详情 |
| 5 | None | https://github.com/whiteHat001/cve-2017-7269picture | POC详情 |
| 6 | fixed msf module for cve-2017-7269 | https://github.com/zcgonvh/cve-2017-7269 | POC详情 |
| 7 | iis6 exploit 2017 CVE-2017-7269 | https://github.com/g0rx/iis6-exploit-2017-CVE-2017-7269 | POC详情 |
| 8 | Ruby Exploit for IIS 6.0 Buffer Overflow (CVE-2017-7269) | https://github.com/slimpagey/IIS_6.0_WebDAV_Ruby | POC详情 |
| 9 | None | https://github.com/homjxi0e/cve-2017-7269 | POC详情 |
| 10 | CVE-2017-7269 | https://github.com/xiaovpn/CVE-2017-7269 | POC详情 |
| 11 | CVE-2017-7269 to webshell or shellcode loader | https://github.com/zcgonvh/cve-2017-7269-tool | POC详情 |
| 12 | CVE-2017-7269利用代码(rb文件) | https://github.com/mirrorblack/CVE-2017-7269 | POC详情 |
| 13 | None | https://github.com/Al1ex/CVE-2017-7269 | POC详情 |
| 14 | None | https://github.com/ThanHuuTuan/CVE-2017-7269 | POC详情 |
| 15 | None | https://github.com/crypticdante/CVE-2017-7269 | POC详情 |
| 16 | CVE-2017-7269 implemented in python3 | https://github.com/denchief1/CVE-2017-7269_Python3 | POC详情 |
| 17 | CVE-2017-7269 implemented in C# | https://github.com/denchief1/CVE-2017-7269 | POC详情 |
| 18 | None | https://github.com/H3xL00m/CVE-2017-7269 | POC详情 |
| 19 | None | https://github.com/n3ov4n1sh/CVE-2017-7269 | POC详情 |
| 20 | None | https://github.com/c0d3cr4f73r/CVE-2017-7269 | POC详情 |
| 21 | Windows Server 2003 & IIS 6.0 - Remote Code Execution | https://github.com/Cappricio-Securities/CVE-2017-7269 | POC详情 |
| 22 | This repository contain an script to exploit CVE-2017-7269 | https://github.com/OmarSuarezDoro/CVE-2017-7269 | POC详情 |
| 23 | None | https://github.com/Sp3c73rSh4d0w/CVE-2017-7269 | POC详情 |
| 24 | None | https://github.com/VanishedPeople/CVE-2017-7269 | POC详情 |
| 25 | None | https://github.com/0xwh1pl4sh/CVE-2017-7269 | POC详情 |
| 26 | None | https://github.com/N3rdyN3xus/CVE-2017-7269 | POC详情 |
| 27 | None | https://github.com/NyxByt3/CVE-2017-7269 | POC详情 |
| 28 | is a PoC tool demonstrating an exploit for a known vulnerability in the WebDAV component of IIS6 | https://github.com/geniuszlyy/CVE-2017-7269 | POC详情 |
| 29 | CVE-2017-7269 | https://github.com/AxthonyV/GenWebDavIISExploit | POC详情 |
| 30 | PoC tool demonstrating an exploit for a known vulnerability in the WebDAV component of IIS6. This tool is designed for educational and research purposes to showcase how the vulnerability can be leveraged to execute arbitrary code on a remote server. | https://github.com/AxthonyV/CVE-2017-7269 | POC详情 |
| 31 | None | https://github.com/h3xcr4ck3r/CVE-2017-7269 | POC详情 |
| 32 | None | https://github.com/n3rdh4x0r/CVE-2017-7269 | POC详情 |
| 33 | is a PoC tool demonstrating an exploit for a known vulnerability in the WebDAV component of IIS6 | https://github.com/geniuszly/CVE-2017-7269 | POC详情 |
| 34 | Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in the ScStoragePathFromUrl function in the WebDAV service that could allow remote attackers to execute arbitrary code via a long header beginning with "If <http://" in a PROPFIND request. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-7269.yaml | POC详情 |
| 35 | None | https://github.com/h3x0v3rl0rd/CVE-2017-7269 | POC详情 |
| 36 | A Rust implementation of the POC for CVE-2017-7269, targeting the WebDAV service in Microsoft Internet Information Services (IIS) 6.0. | https://github.com/nika0x38/CVE-2017-7269 | POC详情 |
暂无评论