CVE-2009-1535
- EPSS 91.83%
- Published 10.06.2009 14:30:00
- Last modified 09.04.2025 00:30:58
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary...
CVE-2003-1567
- EPSS 68.99%
- Published 15.01.2009 00:30:00
- Last modified 09.04.2025 00:30:58
The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or...
- EPSS 9.3%
- Published 15.01.2009 00:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.
- EPSS 67%
- Published 15.10.2008 00:12:15
- Last modified 09.04.2025 00:30:58
Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users ...
- EPSS 26.36%
- Published 29.09.2008 17:17:29
- Last modified 09.04.2025 00:30:58
A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be reproduced by a reliable third party. ...
- EPSS 10.39%
- Published 29.09.2008 17:17:29
- Last modified 09.04.2025 00:30:58
A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to cause a denial of service (browser crash) via a long string in the second argument to the GetObject method. NOTE: this issue was disc...
CVE-2008-0074
- EPSS 2.03%
- Published 12.02.2008 21:00:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.
- EPSS 85.26%
- Published 22.05.2007 19:30:00
- Last modified 09.04.2025 00:30:58
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access pr...
CVE-2006-6579
- EPSS 0.19%
- Published 15.12.2006 19:28:00
- Last modified 09.04.2025 00:30:58
Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write acces...
CVE-2006-6578
- EPSS 1.4%
- Published 15.12.2006 19:28:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demo...