Page 6 of 91 results (0.001 seconds)

CVSS: 5.3EPSS: 59%CPEs: 3EXPL: 1

06 May 2000 — The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path. • https://www.exploit-db.com/exploits/19897 •

CVSS: 7.5EPSS: 20%CPEs: 2EXPL: 0

12 Apr 2000 — IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability. IIS 4.0 y 5.0 permite a atacantes remotos provocar una denegación de servicio enviando muchas URLs con un largo número de caracteres de escape, también conocida como la Vulnerabilidad "Myriad Escaped Characters". • http://www.securityfocus.com/bid/1101 • CWE-20: Improper Input Validation •

CVSS: 7.5EPSS: 83%CPEs: 7EXPL: 1

30 Mar 2000 — IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability. • https://www.exploit-db.com/exploits/19824 •

CVSS: 7.5EPSS: 12%CPEs: 1EXPL: 0

20 Mar 2000 — IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability." • http://www.securityfocus.com/bid/1066 •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

15 Feb 2000 — IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory. • https://www.exploit-db.com/exploits/20310 •

CVSS: 9.8EPSS: 1%CPEs: 2EXPL: 4

02 Feb 2000 — Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. • https://github.com/Cappricio-Securities/CVE-2000-0114 •

CVSS: 7.5EPSS: 70%CPEs: 2EXPL: 1

26 Jan 2000 — Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. • https://www.exploit-db.com/exploits/19742 •

CVSS: 9.1EPSS: 71%CPEs: 3EXPL: 0

11 Jan 2000 — IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. • http://marc.info/?l=bugtraq&m=94770020309953&w=2 •

CVSS: 7.5EPSS: 18%CPEs: 2EXPL: 0

31 Dec 1999 — IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability. • http://support.microsoft.com/support/kb/articles/q192/2/96.asp •

CVSS: 7.5EPSS: 18%CPEs: 1EXPL: 0

31 Dec 1999 — FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time. • http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP •