4 results (0.002 seconds)

CVSS: 10.0EPSS: 96%CPEs: 3EXPL: 6

Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red. • https://www.exploit-db.com/exploits/20930 https://www.exploit-db.com/exploits/16472 https://www.exploit-db.com/exploits/20931 https://www.exploit-db.com/exploits/20933 https://www.exploit-db.com/exploits/20932 http://www.cert.org/advisories/CA-2001-13.html http://www.ciac.org/ciac/bulletins/l-098.shtml http://www.iss.net/security_center/static/6705.php http://www.securityfocus.com/archive/1/191873 http://www.securityfocus.com/bid/2880 https://docs.microso •

CVSS: 5.0EPSS: 92%CPEs: 2EXPL: 0

Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-025 https://exchange.xforce.ibmcloud.com/vulnerabilities/6518 •

CVSS: 5.1EPSS: 95%CPEs: 1EXPL: 2

The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability. • https://www.exploit-db.com/exploits/20335 http://www.securityfocus.com/archive/1/141903 http://www.securityfocus.com/bid/1861 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-084 https://exchange.xforce.ibmcloud.com/vulnerabilities/5441 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 3

The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. • https://www.exploit-db.com/exploits/20399 http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0074.html http://www.securityfocus.com/archive/1/144270 http://www.securityfocus.com/bid/1933 •