Microsoft Internet Information Services vulnerabilities

88 known vulnerabilities affecting microsoft/internet_information_services.

Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
37
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH30MEDIUM48LOW3

Vulnerabilities

Page 5 of 5
CVE-2000-0258HIGHCVSS 7.5v5.02000-04-12
CVE-2000-0258 [HIGH] CWE-20 CVE-2000-0258: IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a lar IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
nvd
CVE-2000-0246MEDIUMCVSS 5.0PoCv5.02000-03-30
CVE-2000-0246 [MEDIUM] CVE-2000-0246: IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mappe IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
nvd
CVE-2000-0071MEDIUMCVSS 5.0v5.02000-01-11
CVE-2000-0071 [MEDIUM] CVE-2000-0071: IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non- IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.
nvd
CVE-1999-0154MEDIUMCVSS 5.0PoCv2.01999-12-31
CVE-1999-0154 [MEDIUM] CVE-1999-0154: IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
nvd
CVE-1999-0412HIGHCVSS 7.5PoCv2.01999-02-19
CVE-1999-0412 [HIGH] CVE-1999-0412: In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
nvd
CVE-1999-0450HIGHCVSS 7.5PoCv2.0v5.01999-01-26
CVE-1999-0450 [HIGH] CVE-1999-0450: In IIS, an attacker could determine a real path using a request for a non-existent URL that would be In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
nvd
CVE-1999-0253HIGHCVSS 7.5v1.0v2.01997-01-01
CVE-1999-0253 [HIGH] CVE-1999-0253: IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP progra IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
nvd
CVE-1999-0233CRITICALCVSS 10.0PoCv1.01996-02-25
CVE-1999-0233 [CRITICAL] CVE-1999-0233: IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
nvd