Microsoft Internet Information Server vulnerabilities
103 known vulnerabilities affecting microsoft/internet_information_server.
Total CVEs
103
CISA KEV
0
Public exploits
38
Exploited in wild
6
Severity breakdown
CRITICAL7HIGH34MEDIUM57LOW5
Vulnerabilities
Page 2 of 6
CVE-1999-0191P4MEDIUMCVSS 6.4PoCv3.01997-09-01
CVE-1999-0191 [MEDIUM] CVE-1999-0191: IIS newdsn.exe CGI script allows remote users to overwrite files.
IIS newdsn.exe CGI script allows remote users to overwrite files.
nvd
CVE-2000-0457P4HIGHCVSS 7.5PoCv4.02000-05-11
CVE-2000-0457 [HIGH] CVE-2000-0457: ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.
nvd
CVE-1999-0412P3HIGHCVSS 7.5PoCv3.0v4.01999-02-19
CVE-1999-0412 [HIGH] CVE-1999-0412: In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
nvd
CVE-1999-0736P4MEDIUMCVSS 5.0PoCv4.01999-05-07
CVE-1999-0736 [MEDIUM] CVE-1999-0736: The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
nvd
CVE-2002-0419P4MEDIUMCVSS 5.0PoCv4.02002-08-12
CVE-2002-0419 [MEDIUM] CWE-200 CVE-2002-0419: Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive inform
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NA
nvd
CVE-1999-0725P4HIGHCVSS 7.1PoCv3.0v4.01999-08-19
CVE-1999-0725 [HIGH] CWE-16 CVE-1999-0725: When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
nvd
CVE-2000-0649P4LOWCVSS 2.6PoCv3.0v4.02000-07-13
CVE-2000-0649 [LOW] CWE-200 CVE-2000-0649: IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 requ
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
nvd
CVE-2001-0506P4HIGHCVSS 7.2PoCv4.02001-09-20
CVE-2001-0506 [HIGH] CVE-2001-0506: Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a S
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
nvd
CVE-1999-1375P4MEDIUMCVSS 5.0PoCv3.0v4.01999-02-11
CVE-1999-1375 [MEDIUM] CVE-1999-1375: FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
nvd
CVE-1999-0450P4HIGHCVSS 7.5PoCv3.0v4.01999-01-26
CVE-1999-0450 [HIGH] CVE-1999-0450: In IIS, an attacker could determine a real path using a request for a non-existent URL that would be
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
nvd
CVE-1999-0154P4MEDIUMCVSS 5.0PoCv3.01999-12-31
CVE-1999-0154 [MEDIUM] CVE-1999-0154: IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot)
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
nvd
CVE-2000-0126P4MEDIUMCVSS 5.0PoCv3.0v4.02000-01-26
CVE-2000-0126 [MEDIUM] CVE-2000-0126: Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.
nvd
CVE-2001-1243P4MEDIUMCVSS 5.0PoCv4.02001-07-04
CVE-2001-1243 [MEDIUM] CVE-2001-1243: Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.
nvd
CVE-2000-0630P4MEDIUMCVSS 5.0PoCv4.02000-07-17
CVE-2000-0630 [MEDIUM] CVE-2000-0630: IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to t
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.
nvd
CVE-1999-1376P3CRITICALCVSS 10.0v4.01999-01-14
CVE-1999-1376 [CRITICAL] CVE-1999-1376: Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers t
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
nvd
CVE-2002-1790P4MEDIUMCVSS 5.0PoCv4.02002-12-31
CVE-2002-1790 [MEDIUM] CVE-2002-1790: The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attacker
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.
nvd
CVE-1999-0448P4MEDIUMCVSS 5.0PoCv4.01999-01-01
CVE-1999-0448 [MEDIUM] CVE-1999-0448: IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote atta
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
nvd
CVE-2002-0147P3HIGHCVSS 7.5v4.02002-04-22
CVE-2002-0147 [HIGH] CVE-2002-0147: Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, an
Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."
nvd
CVE-2002-0149P3HIGHCVSS 7.5v4.02002-04-22
CVE-2002-0149 [HIGH] CVE-2002-0149: Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers
Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.
nvd
CVE-2000-1147P4MEDIUMCVSS 4.6PoCv4.02001-01-09
CVE-2000-1147 [MEDIUM] CVE-2000-1147: Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands v
Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag.
nvd