Vulnerabilities > Microsoft > Internet Information Services > High

DATE CVE VULNERABILITY TITLE RISK
2001-01-09 CVE-2000-1104 Unspecified vulnerability in Microsoft products
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client.
network
low complexity
microsoft
7.5
2000-12-19 CVE-2000-0970 Unspecified vulnerability in Microsoft products
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
network
low complexity
microsoft
7.5
2000-12-19 CVE-2000-0886 Unspecified vulnerability in Microsoft products
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.
network
low complexity
microsoft
7.5
2000-12-19 CVE-2000-0884 Unspecified vulnerability in Microsoft products
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
network
low complexity
microsoft
7.5
2000-05-11 CVE-2000-0457 Unspecified vulnerability in Microsoft products
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.
network
low complexity
microsoft
7.5
1999-02-19 CVE-1999-0412 Unspecified vulnerability in Microsoft products
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
network
low complexity
microsoft
7.5
1999-01-26 CVE-1999-0450 Unspecified vulnerability in Microsoft products
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
network
low complexity
microsoft
7.5
1997-01-01 CVE-1999-0253 Unspecified vulnerability in Microsoft products
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a .
network
low complexity
microsoft
7.5