Vulnerabilities
Vulnerable Software
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
CVSS Score
5.0
EPSS Score
0.517
Published
2000-05-10
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.
CVSS Score
5.0
EPSS Score
0.594
Published
2000-05-06
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
CVSS Score
7.5
EPSS Score
0.203
Published
2000-04-12
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
CVSS Score
5.0
EPSS Score
0.836
Published
2000-03-30
IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability."
CVSS Score
5.0
EPSS Score
0.127
Published
2000-03-20
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.
CVSS Score
2.1
EPSS Score
0.002
Published
2000-02-15
Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.
CVSS Score
5.0
EPSS Score
0.031
Published
2000-02-02
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.
CVSS Score
5.0
EPSS Score
0.701
Published
2000-01-26
IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.
CVSS Score
5.0
EPSS Score
0.049
Published
2000-01-21
IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.
CVSS Score
5.0
EPSS Score
0.714
Published
2000-01-11


Contact Us

Shodan ® - All rights reserved