Vulnerabilities > CVE-1999-0191 - Unspecified vulnerability in Microsoft Internet Information Server 3.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
IIS newdsn.exe CGI script allows remote users to overwrite files.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability. CVE-1999-0191. Remote exploit for windows platform |
id | EDB-ID:20309 |
last seen | 2016-02-02 |
modified | 1997-08-25 |
published | 1997-08-25 |
reporter | Vytis Fedaravicius |
source | https://www.exploit-db.com/download/20309/ |
title | Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | NEWDSN.NASL |
description | The CGI /scripts/tools/newdsn.exe is present. This CGI allows any attacker to create files anywhere on your system if your NTFS permissions are not tight enough, and can be used to overwrite DSNs of existing databases. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10360 |
published | 2000-04-01 |
reporter | This script is Copyright (C) 2000-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10360 |
title | Microsoft IIS newdsn.exe Arbitrary File Creation |
code |
|