Microsoft Internet Information Server vulnerabilities
103 known vulnerabilities affecting microsoft/internet_information_server.
Total CVEs
103
CISA KEV
0
Public exploits
38
Exploited in wild
6
Severity breakdown
CRITICAL7HIGH34MEDIUM57LOW5
Vulnerabilities
Page 6 of 6
CVE-2003-1582P4LOWCVSS 2.6v6.02010-02-05
CVE-2003-1582 [LOW] CWE-79 CVE-2003-1582: Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addr
Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
nvd
CVE-2006-6579P4MEDIUMCVSS 4.4≤ 5.0v3.0+1 more2006-12-15
CVE-2006-6579 [MEDIUM] CVE-2006-6579: Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WIN
Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.
nvd
CVE-1999-0861P4LOWCVSS 2.6v4.01999-08-11
CVE-1999-0861 [LOW] CWE-362 CVE-1999-0861: Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
nvd
← Previous6 / 6