Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
internet information server vulnerabilities and exploits
(subscribe to this query)
NA
CVE-1999-0777
IIS FTP servers may allow a remote malicious user to read or delete files on the server, even if they have "No Access" permissions.
Microsoft Internet Information Server 4.0
Microsoft Commercial Internet System 2.5
NA
CVE-1999-0867
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
Microsoft Commercial Internet System 2.0
Microsoft Internet Information Server 4.0
Microsoft Site Server 3.0
Microsoft Commercial Internet System 2.5
1 EDB exploit
NA
CVE-1999-1451
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote malicious users to read arbitrary files.
Microsoft Internet Information Server 4.0
Microsoft Site Server 3.0
NA
CVE-1999-0861
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
Microsoft Site Server 3.0
Microsoft Commercial Internet System 2.0
Microsoft Internet Information Server 4.0
Microsoft Commercial Internet System 2.5
Microsoft Site Server Commerce 3.0
NA
CVE-2001-0500
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and previous versions allows remote malicious users to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) f...
Microsoft Internet Information Server
Microsoft Index Server 2.0
Microsoft Indexing Service
5 EDB exploits
1 Github repository
NA
CVE-1999-1011
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote malicious users to execute arbitrary commands.
Microsoft Index Server 2.0
Microsoft Internet Information Server 3.0
Microsoft Data Access Components 2.0
Microsoft Data Access Components 2.1
Microsoft Data Access Components 1.5
Microsoft Internet Information Server 4.0
Microsoft Site Server 3.0
2 EDB exploits
1 Article
NA
CVE-2000-0858
Vulnerability in Microsoft Windows NT 4.0 allows remote malicious users to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.
Microsoft Internet Information Server 4.0
Microsoft Windows Nt 4.0
NA
CVE-2001-0146
IIS 5.0 and Microsoft Exchange 2000 allow remote malicious users to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
Microsoft Exchange Server 2000
Microsoft Internet Information Services 5.0
NA
CVE-1999-1591
Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote malicious users to bypass authentication requirements, as demonstrated by connecting ...
Microsoft Internet Information Server 4.0
Microsoft Visual Interdev 6.0
NA
CVE-2000-0024
IIS does not properly canonicalize URLs, potentially allowing remote malicious users to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
Microsoft Site Server 3.0
Microsoft Internet Information Server 4.0
Microsoft Site Server Commerce 3.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »