Description
IISv5 has a "Hit-highlighting" functionality that opens some site object and highlights some part of it, that has had a transversal vulnerability in the past. Now it can be used to bypass the IIS authentication.
Remediation
Protect the files from the NTFS filesystem instead of relying on the
IIS protection.
Microsoft recommends not to use IISv5 and update to IISv6.
References
Related Vulnerabilities
WordPress Plugin WooCommerce-Store Toolkit Privilege Escalation (1.5.6)
WordPress Plugin Namaste! LMS Cross-Site Scripting (2.5.9.3)
WordPress Plugin Avenir-soft Direct Download Multiple Vulnerabilities (1.0)
WordPress Plugin LearnPress-WordPress LMS Multiple Vulnerabilities (4.1.7.3.2)
WordPress Plugin Easy Twitter Feed Cross-Site Scripting (1.1)