CVE
- Id
- 1518
- CVE No.
- CVE-1999-1538
- Status
- Candidate
- Description
- When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator"s password.
- Phase
- Proposed (20010912)
- Votes
- ACCEPT(1) Wall | MODIFY(1) Frech | NOOP(2) Cole, Foat
- Comments
- Frech> XF:iis-ismdll-info(7566)