Vulnerabilities > CVE-2002-0421 - Unspecified vulnerability in Microsoft Windows NT 4.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 8 |
Nessus
NASL family | Web Servers |
NASL id | IIS_AUTHENTIFICATION_MANAGER.NASL |
description | Microsoft IIS installs the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10371 |
published | 2000-04-15 |
reporter | This script is Copyright (C) 2000-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10371 |
title | Microsoft IIS /iisadmpwd/aexp2.htr Password Policy Bypass |