Microsoft Internet Information Server vulnerabilities
103 known vulnerabilities affecting microsoft/internet_information_server.
Total CVEs
103
CISA KEV
0
Public exploits
38
Exploited in wild
6
Severity breakdown
CRITICAL7HIGH34MEDIUM57LOW5
Vulnerabilities
Page 4 of 6
CVE-2002-0075P4HIGHCVSS 7.5v4.02002-04-22
CVE-2002-0075 [HIGH] CVE-2002-0075: Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows rem
Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.
nvd
CVE-2002-0074P4HIGHCVSS 7.5v4.02002-04-22
CVE-2002-0074 [HIGH] CVE-2002-0074: Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS
Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.
nvd
CVE-1999-0737P4MEDIUMCVSS 5.0v4.01999-05-07
CVE-1999-0737 [MEDIUM] CVE-1999-0737: The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
nvd
CVE-2002-0073P4MEDIUMCVSS 5.0v4.02002-04-22
CVE-2002-0073 [MEDIUM] CVE-2002-0073: The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have esta
The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.
nvd
CVE-2002-1181P4MEDIUMCVSS 6.8v4.02002-11-12
CVE-2002-1181 [MEDIUM] CVE-2002-1181: Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft In
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.
nvd
CVE-2001-0335P4MEDIUMCVSS 5.0≤ 5.02001-06-27
CVE-2001-0335 [MEDIUM] CVE-2001-0335: FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted do
FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.
nvd
CVE-1999-0253P4HIGHCVSS 7.5v3.01997-01-01
CVE-1999-0253 [HIGH] CVE-1999-0253: IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP progra
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
nvd
CVE-2000-0167P4LOWCVSS 2.1PoCv4.02000-02-15
CVE-2000-0167 [LOW] CVE-2000-0167: IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.
nvd
CVE-1999-1451P4MEDIUMCVSS 5.0v4.01999-12-31
CVE-1999-1451 [MEDIUM] CVE-1999-1451: The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.
nvd
CVE-2000-0025P4MEDIUMCVSS 5.0v4.01999-12-21
CVE-2000-0025 [MEDIUM] CVE-2000-0025: IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.
nvd
CVE-2000-0770P4MEDIUMCVSS 6.4v4.02000-10-20
CVE-2000-0770 [MEDIUM] CVE-2000-0770: IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folder
IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.
nvd
CVE-2001-0709P4MEDIUMCVSS 5.0≤ 4.02001-09-20
CVE-2001-0709 [MEDIUM] CVE-2001-0709: Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain
Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.
nvd
CVE-1999-0012P4HIGHCVSS 7.0v4.01998-02-06
CVE-1999-0012 [HIGH] CWE-290 CVE-1999-0012: Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for fi
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
nvd
CVE-2001-0334P4HIGHCVSS 7.5≤ 5.02001-06-27
CVE-2001-0334 [HIGH] CWE-131 CVE-2001-0334: FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildca
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.
nvd
CVE-2000-0258P4HIGHCVSS 7.5v4.02000-04-12
CVE-2000-0258 [HIGH] CWE-20 CVE-2000-0258: IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a lar
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
nvd
CVE-2000-0024P4MEDIUMCVSS 6.4v4.01999-12-21
CVE-2000-0024 [MEDIUM] CVE-2000-0024: IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access rest
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
nvd
CVE-1999-1233P4HIGHCVSS 7.5v4.01999-12-31
CVE-1999-1233 [HIGH] CVE-1999-1233: IIS 4.0 does not properly restrict access for the initial session request from a user's IP address i
IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.
nvd
CVE-2001-0004P4MEDIUMCVSS 5.0v4.02001-02-12
CVE-2001-0004 [MEDIUM] CVE-2001-0004: IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs b
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.
nvd
CVE-2003-0225P4MEDIUMCVSS 5.0v4.02003-06-09
CVE-2003-0225 [MEDIUM] CVE-2003-0225: The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does
The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.
nvd
CVE-2000-0304P4MEDIUMCVSS 5.0v4.02000-05-10
CVE-2000-0304 [MEDIUM] CVE-2000-0304: Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
nvd