VendorsMicrosoftinternet_information_services2.0
Vulnerabilities

Microsoft Internet Information 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-1999-0450
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
Published 2000-02-04 · Modified
7.51 PoCEPSS 0.190
CVE-1999-0412
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
Published 1999-09-29 · Modified
7.51 PoCEPSS 0.102
CVE-1999-0253
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
Published 2000-02-04 · Modified
7.5EPSS 0.080
CVE-1999-0154
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
Published 2001-09-12 · Modified
5.01 PoCEPSS 0.400
CVE-1999-0281
Denial of service in IIS using long URLs.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.128
CVE-2006-6579
Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.
Published 2006-12-15 · Modified
4.4EPSS 0.014
CVE-2000-0649
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
Published 2000-08-03 · Modified
2.61 PoCEPSS 0.766