CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1518 | CVE-1999-1538 | Candidate | When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator"s password. | Proposed (20010912) | ACCEPT(1) Wall | MODIFY(1) Frech | NOOP(2) Cole, Foat | Frech> XF:iis-ismdll-info(7566) | View |
2714 | CVE-2000-1147 | Candidate | Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag. | Modified (20010116-01) | ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Cole | RECAST(1) LeBlanc | REVIEWING(1) Christey | Frech> XF:iis-isapi-asp-bo(5510) | Christey> Consult Microsoft on this one. | LeBlanc> This one was already fixed in several hotfixes when it was | found. I"m not sure what the content decision is on this. It is a valid | problem, but it was already fixed when announced. I will go along with | an accept vote once it is modified to show fixes. | View |
1649 | CVE-2000-0071 | Candidate | IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. | Proposed (20000125) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Baker | REJECT(1) Christey | Frech> XF:iis-ida-idq-paths | Christey> Consider adding: | ADDREF BID:1065 | BUGTRAQ:20000309 Enumerate Root Web Server Directory Vulnerability for IIS 4.0 | Are there really 2 different threads on the same problem? | | Also consider XF:iis-root-enum | | May also be a dupe of CVE-1999-0450 (BID:194) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Appears to be a duplicate of CVE-2000-0098. Confirm with | Microsoft, and if it is a duplicate, then REJECT this | candidate. | CHANGE> [Christey changed vote from REVIEWING to REJECT] | Christey> Confirmed duplicate by Microsoft. | Christey> iis-ida-idq-paths(4346) is obsolete; ensure | http-indexserver-path(3890) is added to CVE-2000-0098. | View |
1355 | CVE-1999-1375 | Candidate | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | Frech> XF:iis-fso-read-files(7558) | Christey> Explicitly mention IIS | View |
1692 | CVE-2000-0114 | Candidate | Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. | Proposed (20000208) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:iis-frontpage-info | Christey> Acknowledged via personal communication with Microsoft | personnel. | | May be the same as BID:1174 and/or BID:1433 (both mention | FrontPage, but one mentions shtml.exe and another mentions | shtml.dll) | Christey> [note to self: review comments by Mark Burnett] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
Page 154 of 20943, showing 5 records out of 104715 total, starting on record 766, ending on 770