CVE-2001-0507 – Microsoft IIS 5.0 - In-Process Table Privilege Escalation
https://notcve.org/view.php?id=CVE-2001-0507
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability. • https://www.exploit-db.com/exploits/21072 http://online.securityfocus.com/archive/1/205069 http://www.ciac.org/ciac/bulletins/l-132.shtml http://www.osvdb.org/5607 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044 https://exchange.xforce.ibmcloud.com/vulnerabilities/6985 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A909 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A912 •
CVE-2001-0508
https://notcve.org/view.php?id=CVE-2001-0508
Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request. • http://online.securityfocus.com/archive/1/182579 http://www.iss.net/security_center/static/6982.php http://www.osvdb.org/5606 http://www.osvdb.org/5633 http://www.securityfocus.com/bid/2690 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044 •
CVE-2001-0506 – Microsoft IIS 4.0/5.0 - SSI Buffer Overrun Privilege Escalation
https://notcve.org/view.php?id=CVE-2001-0506
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability. • https://www.exploit-db.com/exploits/21071 http://marc.info/?l=bugtraq&m=99802093532233&w=2 http://online.securityfocus.com/archive/1/242541 http://www.ciac.org/ciac/bulletins/l-132.shtml http://www.securityfocus.com/bid/3190 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044 https://exchange.xforce.ibmcloud.com/vulnerabilities/6984 •
CVE-2001-1243 – Microsoft IIS 4.0/5.0 - Device File Local Denial of Service
https://notcve.org/view.php?id=CVE-2001-1243
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject. • https://www.exploit-db.com/exploits/20989 https://www.exploit-db.com/exploits/20991 http://www.iss.net/security_center/static/6800.php http://www.securityfocus.com/archive/1/194919 http://www.securityfocus.com/bid/2973 •
CVE-2001-0151 – Microsoft IIS 5.0 - WebDAV Denial of Service
https://notcve.org/view.php?id=CVE-2001-0151
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests. • https://www.exploit-db.com/exploits/20664 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-016 https://exchange.xforce.ibmcloud.com/vulnerabilities/6205 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A90 •