Vulnerabilities > Microsoft > Internet Information Server > High

DATE CVE VULNERABILITY TITLE RISK
2000-05-11 CVE-2000-0457 Unspecified vulnerability in Microsoft products
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.
network
low complexity
microsoft
7.5
1999-12-31 CVE-1999-1591 Authentication vulnerability in Microsoft VisualInterDev 6.0 - IIS4- Management With No
Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.
network
low complexity
microsoft
7.5
1999-12-31 CVE-1999-1233 Unspecified vulnerability in Microsoft Internet Information Server 4.0
IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.
network
low complexity
microsoft
7.5
1999-02-19 CVE-1999-0412 Unspecified vulnerability in Microsoft products
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
network
low complexity
microsoft
7.5
1999-01-26 CVE-1999-0450 Unspecified vulnerability in Microsoft products
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
network
low complexity
microsoft
7.5
1999-01-26 CVE-1999-0449 Unspecified vulnerability in Microsoft Internet Information Server 4.0
The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.
network
low complexity
microsoft
7.8
1997-01-01 CVE-1999-0253 Unspecified vulnerability in Microsoft products
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a .
network
low complexity
microsoft
7.5