Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2006-6579
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.
0
Attacker Value
Unknown
CVE-2000-0631
Disclosure Date: July 14, 2000 (last updated February 22, 2025)
An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.
0
Attacker Value
Unknown
CVE-2000-0649
Disclosure Date: July 13, 2000 (last updated February 22, 2025)
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
0
Attacker Value
Unknown
CVE-2000-0246
Disclosure Date: March 30, 2000 (last updated February 22, 2025)
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
0
Attacker Value
Unknown
CVE-2000-0114
Disclosure Date: February 02, 2000 (last updated February 22, 2025)
Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.
0
Attacker Value
Unknown
CVE-2000-0126
Disclosure Date: January 26, 2000 (last updated February 22, 2025)
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.
0
Attacker Value
Unknown
CVE-2000-0071
Disclosure Date: January 11, 2000 (last updated February 22, 2025)
IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.
0
Attacker Value
Unknown
CVE-1999-0154
Disclosure Date: December 31, 1999 (last updated February 22, 2025)
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
0
Attacker Value
Unknown
CVE-1999-1223
Disclosure Date: December 31, 1999 (last updated February 22, 2025)
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
0
Attacker Value
Unknown
CVE-1999-1035
Disclosure Date: December 31, 1999 (last updated February 22, 2025)
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
0