Vulnerabilities > CVE-2003-0224 - Unspecified vulnerability in Microsoft Internet Information Services 5.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS03-018.NASL |
description | The remote host is running a version of IIS that contains various flaws that could allow remote attackers to disable this service remotely and local attackers (or remote attackers with the ability to upload arbitrary files on this server) to gain SYSTEM level access on this host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11683 |
published | 2003-06-02 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11683 |
title | MS03-018: Cumulative Patch for Internet Information Services (11114) |
code |
|
Oval
accepted | 2011-05-16T04:03:05.925-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
description | Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun." | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:483 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2004-01-14T12:00:00.000-04:00 | ||||||||||||||||||||||||
title | IIS Server Side Include Web Pages Buffer Overrun | ||||||||||||||||||||||||
version | 34 |
References
- http://marc.info/?l=ntbugtraq&m=105431767100944&w=2
- http://marc.info/?l=ntbugtraq&m=105431767100944&w=2
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A483
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A483