{"id":30043051,"url":"https://github.com/vysecurity/iis_exploit","last_synced_at":"2026-02-11T04:32:12.294Z","repository":{"id":97561795,"uuid":"86357245","full_name":"vysecurity/IIS_exploit","owner":"vysecurity","description":"Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with \"If: \u003chttp://\" in a PROPFIND request, as exploited in the wild in July or August 2016.","archived":false,"fork":false,"pushed_at":"2017-03-27T02:33:03.000Z","size":7,"stargazers_count":3,"open_issues_count":0,"forks_count":215,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-08-07T04:51:26.488Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/vysecurity.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2017-03-27T16:15:02.000Z","updated_at":"2025-04-07T15:27:55.000Z","dependencies_parsed_at":null,"dependency_job_id":"6f5e7cc5-4246-4871-a8ea-58d3974fcc8a","html_url":"https://github.com/vysecurity/IIS_exploit","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/vysecurity/IIS_exploit","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vysecurity%2FIIS_exploit","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vysecurity%2FIIS_exploit/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vysecurity%2FIIS_exploit/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vysecurity%2FIIS_exploit/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/vysecurity","download_url":"https://codeload.github.com/vysecurity/IIS_exploit/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/vysecurity%2FIIS_exploit/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29327091,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-11T03:52:29.695Z","status":"ssl_error","status_checked_at":"2026-02-11T03:52:23.094Z","response_time":97,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-08-07T04:50:23.997Z","updated_at":"2026-02-11T04:32:12.284Z","avatar_url":"https://github.com/vysecurity.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# CVE-2017-7269\n\n[Description]\nBuffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with \"If: \u0026lt;http://\" in a PROPFIND request, as exploited in the wild in July or August 2016.\n\n\n[Additional Information]\nthe ScStoragePathFromUrl function is called twice\n\n[Vulnerability Type]\nBuffer overflow\n\n[Vendor of Product]\nMicrosoft\n\n[Affected Product Code Base]\nWindows Server 2003 R2\n\n[Affected Component]\nScStoragePathFromUrl\n\n[Attack Type]\nRemote\n\n[Impact Code execution]\ntrue\n\n[Attack Vectors]\ncrafted PROPFIND data\n\n[Has vendor confirmed or acknowledged the vulnerability?]\ntrue\n\n[Discoverer]\nZhiniang Peng and Chen Wu.\n\nInformation Security Lab \u0026 School of Computer Science \u0026 Engineering, South China University of Technology \nGuangzhou, China\n\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvysecurity%2Fiis_exploit","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fvysecurity%2Fiis_exploit","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvysecurity%2Fiis_exploit/lists"}