Microsoft

Internet Information Server

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 27.07%
  • Veröffentlicht 19.02.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.

Exploit
  • EPSS 73.17%
  • Veröffentlicht 11.02.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

  • EPSS 29.62%
  • Veröffentlicht 09.02.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.

  • EPSS 13.24%
  • Veröffentlicht 27.01.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

  • EPSS 11.24%
  • Veröffentlicht 27.01.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.

  • EPSS 36.24%
  • Veröffentlicht 26.01.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.

  • EPSS 32.43%
  • Veröffentlicht 26.01.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

  • EPSS 6.82%
  • Veröffentlicht 24.01.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.

  • EPSS 54.89%
  • Veröffentlicht 14.01.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

Exploit
  • EPSS 56.6%
  • Veröffentlicht 14.01.1999 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator'...