Vulnerabilities > Microsoft > Internet Information Server > High

DATE CVE VULNERABILITY TITLE RISK
2002-04-22 CVE-2002-0075 Unspecified vulnerability in Microsoft products
Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.
network
low complexity
microsoft
7.5
2002-04-22 CVE-2002-0074 Unspecified vulnerability in Microsoft products
Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.
network
low complexity
microsoft
7.5
2002-04-22 CVE-2002-0071 Buffer Overflow vulnerability in Microsoft products
Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.
network
low complexity
microsoft
7.5
2001-09-20 CVE-2001-0506 Buffer Overrun Privelege Elevation vulnerability in Microsoft products
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
local
low complexity
microsoft
7.2
2001-06-27 CVE-2001-0334 Incorrect Calculation of Buffer Size vulnerability in Microsoft Internet Information Server
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.
network
low complexity
microsoft CWE-131
7.5
2001-06-27 CVE-2001-0333 Unspecified vulnerability in Microsoft Internet Information Server
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding ..
network
low complexity
microsoft
7.5
2001-01-09 CVE-2000-1104 Unspecified vulnerability in Microsoft products
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client.
network
low complexity
microsoft
7.5
2000-12-19 CVE-2000-0970 Unspecified vulnerability in Microsoft products
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
network
low complexity
microsoft
7.5
2000-12-19 CVE-2000-0886 Unspecified vulnerability in Microsoft products
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.
network
low complexity
microsoft
7.5
2000-12-19 CVE-2000-0884 Unspecified vulnerability in Microsoft products
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
network
low complexity
microsoft
7.5