CVE-2001-0507
- EPSS 2.32%
- Published 20.09.2001 04:00:00
- Last modified 03.04.2025 01:03:51
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
CVE-2001-0506
- EPSS 77.61%
- Published 20.09.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevatio...
- EPSS 19.54%
- Published 04.07.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, ...
- EPSS 80%
- Published 02.06.2001 04:00:00
- Last modified 03.04.2025 01:03:51
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
- EPSS 12.28%
- Published 02.06.2001 04:00:00
- Last modified 03.04.2025 01:03:51
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
- EPSS 55.87%
- Published 12.02.2001 05:00:00
- Last modified 03.04.2025 01:03:51
FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.
- EPSS 76.17%
- Published 12.02.2001 05:00:00
- Last modified 03.04.2025 01:03:51
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Read...
CVE-2000-1104
- EPSS 12.83%
- Published 09.01.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message b...
CVE-2000-0970
- EPSS 38.46%
- Published 19.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Mar...
- EPSS 49.17%
- Published 19.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.