Microsoft Internet Information Services vulnerabilities
88 known vulnerabilities affecting microsoft/internet_information_services.
Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
38
Exploited in wild
7
Severity breakdown
CRITICAL7HIGH31MEDIUM47LOW3
Vulnerabilities
Page 4 of 5
CVE-2002-0075P4HIGHCVSS 7.5v5.02002-04-22
CVE-2002-0075 [HIGH] CVE-2002-0075: Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows rem
Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.
nvd
CVE-2002-0074P4HIGHCVSS 7.5v5.02002-04-22
CVE-2002-0074 [HIGH] CVE-2002-0074: Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS
Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.
nvd
CVE-2002-0073P4MEDIUMCVSS 5.0v5.02002-04-22
CVE-2002-0073 [MEDIUM] CVE-2002-0073: The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have esta
The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.
nvd
CVE-2001-0902P4HIGHCVSS 7.5v5.02001-11-20
CVE-2001-0902 [HIGH] CVE-2001-0902: Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes
Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.
nvd
CVE-2002-1181P4MEDIUMCVSS 6.8v5.02002-11-12
CVE-2002-1181 [MEDIUM] CVE-2002-1181: Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft In
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.
nvd
CVE-1999-0253P4HIGHCVSS 7.5v1.0v2.01997-01-01
CVE-1999-0253 [HIGH] CVE-1999-0253: IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP progra
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
nvd
CVE-2002-1180P4HIGHCVSS 7.5v5.02002-11-12
CVE-2002-1180 [HIGH] CVE-2002-1180: A typographical error in the script source access permissions for Internet Information Server (IIS)
A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."
nvd
CVE-2000-0770P4MEDIUMCVSS 6.4v5.02000-10-20
CVE-2000-0770 [MEDIUM] CVE-2000-0770: IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folder
IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.
nvd
CVE-2000-0258P4HIGHCVSS 7.5v5.02000-04-12
CVE-2000-0258 [HIGH] CWE-20 CVE-2000-0258: IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a lar
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
nvd
CVE-2002-1182P4MEDIUMCVSS 5.0v5.02002-11-12
CVE-2002-1182 [MEDIUM] CVE-2002-1182: IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV re
IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.
nvd
CVE-2001-0146P4MEDIUMCVSS 5.0v5.02001-06-02
CVE-2001-0146 [MEDIUM] CVE-2001-0146: IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allo
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
nvd
CVE-2001-0004P4MEDIUMCVSS 5.0v5.02001-02-12
CVE-2001-0004 [MEDIUM] CVE-2001-0004: IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs b
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.
nvd
CVE-2003-0225P4MEDIUMCVSS 5.0v5.02003-06-09
CVE-2003-0225 [MEDIUM] CVE-2003-0225: The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does
The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.
nvd
CVE-2001-0508P4MEDIUMCVSS 5.0v5.02001-09-20
CVE-2001-0508 [MEDIUM] CVE-2001-0508: Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long,
Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.
nvd
CVE-2000-0304P4MEDIUMCVSS 5.0v5.02000-05-10
CVE-2000-0304 [MEDIUM] CVE-2000-0304: Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
nvd
CVE-2002-0224P4MEDIUMCVSS 5.0v5.02002-05-16
CVE-2002-0224 [MEDIUM] CVE-2002-0224: The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Micros
The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
nvd
CVE-2002-1717P4MEDIUMCVSS 5.0v5.12002-12-31
CVE-2002-1717 [MEDIUM] CWE-200 CVE-2002-1717: Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via
Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /_vti_pvt/botinfs.cnf, (3) /_vti_pvt/bots.cnf, or (4) /_vti_pvt/linkinfo.cnf.
nvd
CVE-2000-0746P4HIGHCVSS 7.5v5.02000-10-20
CVE-2000-0746 [HIGH] CVE-2000-0746: Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attack
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross
nvd
CVE-2000-0631P4MEDIUMCVSS 5.0v5.02000-07-14
CVE-2000-0631 [MEDIUM] CVE-2000-0631: An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to
An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.
nvd
CVE-2002-1718P4MEDIUMCVSS 5.0v5.12002-12-31
CVE-2002-1718 [MEDIUM] CWE-200 CVE-2002-1718: Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a
Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claimed using an HTTP request for colegal.htm that contains .. (dot dot) sequences.
nvd