Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
iis vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2007-6498
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and previous versions allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield parameter to accounts...
Hosting Controller Hosting Controller 6.1 Hotfix 3.3
1 EDB exploit
7.5
CVSSv2
CVE-2007-2897
Microsoft Internet Information Services (IIS) 6.0 allows remote malicious users to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute ar...
Microsoft Internet Information Server 6.0
10
CVSSv2
CVE-2007-2815
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote malicious users to bypass NTLM and basic authentication mechanisms and access private web dire...
Microsoft Internet Information Services 5.0
1 EDB exploit
4.3
CVSSv2
CVE-2007-1278
Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote malicious users to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web ro...
Adobe Coldfusion 6.1
Adobe Jrun 4.0
Adobe Coldfusion 7.0
7.8
CVSSv2
CVE-2007-0087
Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote malicious users to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE:...
Microsoft Internet Information Server
5
CVSSv2
CVE-2006-5858
Adobe ColdFusion MX 7 up to and including 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote malicious users to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file.
Adobe Coldfusion
Adobe Jrun 4.0
7.5
CVSSv2
CVE-2006-6578
Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows malicious users to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com w...
Microsoft Internet Information Services 5.1
4.3
CVSSv2
CVE-2006-0032
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote malicious users to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an...
Microsoft Windows 2003 Server Datacenter Edition
Microsoft Windows 2003 Server Enterprise Edition Itanium
Microsoft Windows 2003 Server Standard 64-bit
Microsoft Windows 2003 Server Web
Microsoft Windows Xp
Microsoft Windows 2000
Microsoft Windows 2003 Server Datacenter Edition Itanium
Microsoft Windows 2003 Server R2
Microsoft Windows 2003 Server Enterprise 64-bit
Microsoft Windows 2003 Server Sp1
Microsoft Windows 2003 Server Standard
Microsoft Windows 2000 Resource Kit
Microsoft Windows 2003 Server Enterprise Edition
1 EDB exploit
6.5
CVSSv2
CVE-2006-0026
Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote malicious users to execute arbitrary code via crafted Active Server Pages (ASP).
Microsoft Internet Information Services 5.0
Microsoft Internet Information Server 6.0
1 EDB exploit
4.3
CVSSv2
CVE-2006-1394
Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 prior to 3.2.1b, and 3.3 prior to 3.3.0a allow remote malicious users to inject arbitrary web script or HT...
University Of Washington Pubcookie 3.1.0
University Of Washington Pubcookie 3.1.1
University Of Washington Pubcookie 3.2.0
University Of Washington Pubcookie 3.2.1
University Of Washington Pubcookie 3.2.1a
University Of Washington Pubcookie 3.0.0
University Of Washington Pubcookie 3.3.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »