Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-1899

CWE-119Buffer Overflow4 documents4 sources
Severity
4.3MEDIUM
EPSS
86.0%
top 0.61%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedSep 15
Latest updateMay 13

Description

Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

🔴Vulnerability Details

2
GHSA
GHSA-74ch-7c47-jp63: Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 52022-05-13
CVEList
CVE-2010-1899: Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 52010-09-15

💥Exploits & PoCs

1
Exploit-DB
Microsoft IIS 6.0 - ASP Stack Overflow Stack Exhaustion (Denial of Service) (MS10-065)2010-10-01
CVE-2010-1899 (MEDIUM CVSS 4.3) | Stack consumption vulnerability in | cvebase.io