Vulnerabilities > CVE-1999-1538 - Remote Web-Based Administration vulnerability in Microsoft Internet Information Server 4.0
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | NT IIS4 Remote Web-Based Administration Vulnerability. CVE-1999-1538. Remote exploit for windows platform |
id | EDB-ID:19147 |
last seen | 2016-02-02 |
modified | 1999-01-14 |
published | 1999-01-14 |
reporter | Mnemonix |
source | https://www.exploit-db.com/download/19147/ |
title | NT IIS4 - Remote Web-Based Administration Vulnerability |
Nessus
NASL family | Web Servers |
NASL id | IISADMIN.NASL |
description | When Microsoft Internet Information Server (IIS) 4.0 is upgraded from version 2.0 or 3.0 the ism.dll file is left in the /scripts/iisadmin directory. This script discloses sensitive information via a specially crafted URL which could lead to elevated privileges. An attacker could use this to gain access to the administrator |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10358 |
published | 2000-04-01 |
reporter | This script is Copyright (C) 2000-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10358 |
title | Microsoft IIS /iisadmin Unrestricted Access |
code |
|