Page 9 of 84 results (0.001 seconds)

CVSS: 9.1EPSS: 0%CPEs: 4EXPL: 1

26 Jan 1999 — In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). • https://www.exploit-db.com/exploits/19152 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 1

01 Jun 1997 — Denial of service in IIS using long URLs. • https://www.exploit-db.com/exploits/20802 •

CVSS: 7.5EPSS: 1%CPEs: 3EXPL: 0

01 Jan 1997 — IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. • http://www.securityfocus.com/bid/1814 •

CVSS: 10.0EPSS: 16%CPEs: 1EXPL: 1

25 Feb 1996 — IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. • https://www.exploit-db.com/exploits/20445 •