cbcvebase.

Microsoft Internet Information Services vulnerabilities

88 known vulnerabilities affecting microsoft/internet_information_services.

Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
38
Exploited in wild
7
Severity breakdown
CRITICAL7HIGH31MEDIUM47LOW3

Vulnerabilities

Page 5 of 5
CVE-2000-1104P4HIGHCVSS 7.5v5.02001-01-09
CVE-2000-1104 [HIGH] CVE-2000-1104: Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE- Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.
nvd
CVE-2002-1695P4MEDIUMCVSS 5.0v5.02002-12-31
CVE-2002-1695 [MEDIUM] CVE-2002-1695: Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.
nvd
CVE-2003-0223P4MEDIUMCVSS 6.8v5.02003-06-09
CVE-2003-0223 [MEDIUM] CVE-2003-0223: Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsof Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.
nvd
CVE-2002-1908P4MEDIUMCVSS 5.0v5.02002-12-31
CVE-2002-1908 [MEDIUM] CVE-2002-1908: Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.
nvd
CVE-2001-0096P4MEDIUMCVSS 5.0v5.02001-02-12
CVE-2001-0096 [MEDIUM] CVE-2001-0096: FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of s FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.
nvd
CVE-2002-1694P4MEDIUMCVSS 5.0v5.02002-12-31
CVE-2002-1694 [MEDIUM] CVE-2002-1694: Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_ Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.
nvd
CVE-2006-6579P4MEDIUMCVSS 4.4v1.0v2.02006-12-15
CVE-2006-6579 [MEDIUM] CVE-2006-6579: Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WIN Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.
nvd
CVE-2001-0544P4LOWCVSS 2.1v5.02001-10-30
CVE-2001-0544 [LOW] CVE-2001-0544: IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produc IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table.
nvd
Microsoft Internet Information Services vulnerabilities | cvebase