Page 3 of 39 results (0.009 seconds)

CVSS: 9.1EPSS: 0%CPEs: 3EXPL: 0

21 Dec 1999 — IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ246401 •

CVSS: 7.5EPSS: 1%CPEs: 3EXPL: 0

21 Dec 1999 — IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ238606 •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 1

19 Aug 1999 — When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". • https://www.exploit-db.com/exploits/19361 • CWE-16: Configuration •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 1

11 Aug 1999 — Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. • https://www.exploit-db.com/exploits/19457 • CWE-20: Improper Input Validation •

CVSS: 5.9EPSS: 0%CPEs: 5EXPL: 0

11 Aug 1999 — Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ244613 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 10.0EPSS: 68%CPEs: 7EXPL: 2

19 Jul 1999 — The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. • https://www.exploit-db.com/exploits/19425 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.5EPSS: 17%CPEs: 2EXPL: 0

07 Jul 1999 — IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL. • http://marc.info/?l=ntbugtraq&m=93138827329577&w=2 •

CVSS: 7.5EPSS: 89%CPEs: 2EXPL: 0

06 Jul 1999 — The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. • http://marc.info/?l=ntbugtraq&m=93138827429589&w=2 •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 1

19 Feb 1999 — In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. • https://www.exploit-db.com/exploits/19376 •

CVSS: 7.5EPSS: 8%CPEs: 2EXPL: 2

11 Feb 1999 — FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. • https://www.exploit-db.com/exploits/19194 •