// For flags

CVE-2007-2897

 

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute arbitrary code after connecting a data stream to a device COM port; via requests for a URI containing a '/' immediately before and after the name of a DOS device, as demonstrated by the /AUX/.aspx URI, which bypasses a blacklist for DOS device requests.

Microsoft Internet Information Services (IIS) 6.0 permite a atacantes remotos provocar una denegación de servicio (inestabilidad del servidor o cuelgue del dispositivo), y posiblemente obtener información sensible (tráfico de comunicación del dispositivo); y podría permitir a atacantes con acceso físico ejecutar código de su elección tras conectar un flujo de datos a un puerto COM del dispositivo; mediante peticiones a un URI conteniendo un '\' inmediatamente antes y después del nombre de un dispositivo DOS, como se ha demostrado con el URI /AUX/.aspx , lo cual evita una lista negra para peticiones de dispositivos DOS.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-05-29 CVE Reserved
  • 2007-05-30 CVE Published
  • 2024-04-02 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Internet Information Server
Search vendor "Microsoft" for product "Internet Information Server"
6.0
Search vendor "Microsoft" for product "Internet Information Server" and version "6.0"
-
Affected