Product:

Internet_information_server

(Microsoft)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 108
Date Id Summary Products Score Patch Annotated
1999-08-11 CVE-1999-0861 Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. Commercial_internet_system, Internet_information_server, Site_server, Site_server_commerce N/A
1999-08-19 CVE-1999-0725 When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". Internet_information_server N/A
1999-09-23 CVE-1999-0777 IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. Commercial_internet_system, Internet_information_server N/A
1999-12-21 CVE-2000-0025 IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. Internet_information_server, Site_server, Site_server_commerce N/A
1999-12-21 CVE-2000-0024 IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. Internet_information_server, Site_server, Site_server_commerce N/A
2000-10-20 CVE-2000-0746 Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities. Frontpage, Internet_information_server, Internet_information_services N/A
2009-08-31 CVE-2009-3023 Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability." Internet_information_server N/A
1997-01-01 CVE-1999-0253 IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. Internet_information_server, Internet_information_services N/A
1997-06-01 CVE-1999-0281 Denial of service in IIS using long URLs. Internet_information_server, Internet_information_services N/A
1998-02-06 CVE-1999-0012 Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. Frontpage, Internet_information_server, Personal_web_server, Enterprise_server, Fasttrack_server N/A