This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:microsoft:internet_information_server:5.0
Detail
VendorMicrosoftFirst view 1999-01-26
ProductInternet Information ServerLast view 2008-02-12
Version5.0TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:microsoft:internet_information_server

Activity : Yearly

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
 DateAlertAccess VectorAccess ComplexityAuthentification
7.22008-02-12CVE-2008-0074LocalLowNone Requ...
4.42006-12-15CVE-2006-6579LocalMediumNone Requ...
6.52006-07-11CVE-2006-0026NetworkLowRequires ...
52005-08-23CVE-2005-2678NetworkLowNone Requ...
4.32005-07-05CVE-2005-2089NetworkMediumNone Requ...
Hide | Show 20 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
52004-11-03CVE-2003-0718NetworkLowNone Requ...
52003-06-09CVE-2003-0226NetworkLowNone Requ...
52003-06-09CVE-2003-0225NetworkLowNone Requ...
102003-06-09CVE-2003-0224NetworkLowNone Requ...
6.82003-06-09CVE-2003-0223NetworkMediumNone Requ...
52002-12-31CVE-2002-1908NetworkLowNone Requ...
52002-12-31CVE-2002-1790NetworkLowNone Requ...
52002-12-31CVE-2002-1745NetworkLowNone Requ...
52002-12-31CVE-2002-1744NetworkLowNone Requ...
6.82002-12-31CVE-2002-1700NetworkMediumNone Requ...
52002-12-31CVE-2002-1695NetworkLowNone Requ...
52002-12-31CVE-2002-1694NetworkLowNone Requ...
52002-11-12CVE-2002-1182NetworkLowNone Requ...
6.82002-11-12CVE-2002-1181NetworkMediumNone Requ...
7.52002-11-12CVE-2002-1180NetworkLowNone Requ...
7.52002-11-12CVE-2002-0869NetworkLowNone Requ...
7.52002-10-04CVE-2002-0862NetworkLowNone Requ...
2.62002-08-12CVE-2002-0422NetworkHighNone Requ...
52002-08-12CVE-2002-0419NetworkLowNone Requ...

CWE : Common Weakness Enumeration

%idName
75% (3)CWE-200Information Exposure
25% (1)CWE-264Permissions, Privileges, and Access Controls

CAPEC : Common Attack Pattern Enumeration & Classificatio

idName
CAPEC-19Embedding Scripts within Scripts
CAPEC-33HTTP Request Smuggling
CAPEC-38Leveraging/Manipulating Configuration File Search Paths
CAPEC-47Buffer Overflow via Parameter Expansion
CAPEC-71Using Unicode Encoding to Bypass Validation Logic
Hide | Show 5 More...
idName
CAPEC-81Web Logs Tampering
CAPEC-100Overflow Buffers
CAPEC-105HTTP Request Splitting
CAPEC-123Buffer Attacks
CAPEC-198Cross-Site Scripting in Error Pages

Oval Markup Language : Definitions

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
OvalIDName
oval:org.mitre.oval:def:927IIS5.0 Specialized Header Vulnerability
oval:org.mitre.oval:def:44IIS Web Server Folder Traversal
oval:org.mitre.oval:def:191IIS Web Server File Request Parsing
oval:org.mitre.oval:def:90IIS Denial of Service via WebDAV
oval:org.mitre.oval:def:78Windows 2000 IIS Directory Traversal Command Execution (Test 1)
Hide | Show 20 More...
idName
oval:org.mitre.oval:def:37Windows NT IIS Directory Traversal Command Execution (Test 1)
oval:org.mitre.oval:def:1051Windows 2000 IIS Directory Traversal Command Execution (Test 2)
oval:org.mitre.oval:def:1018Windows NT IIS Directory Traversal Command Execution (Test 2)
oval:org.mitre.oval:def:912Windows 2000 IIS System File Listing Privilege Elevation Vulnerability
oval:org.mitre.oval:def:909Windows NT IIS System File Listing Privilege Elevation Vulnerability
oval:org.mitre.oval:def:45DEPRECATED: Windows NT HTR ISAPI Buffer Overflow
oval:org.mitre.oval:def:130DEPRECATED: Windows 2000 HTR ISAPI Buffer Overflow
oval:org.mitre.oval:def:12413Buffer overrun in HTR ISAPI extension
oval:org.mitre.oval:def:12315Access violation in URL error handling
oval:org.mitre.oval:def:35DEPRECATED: Windows 2000 IIS FTP Connection Status Request Denial of Service
oval:org.mitre.oval:def:24DEPRECATED: Windows NT IIS FTP Connection Status Request Denial of Service
oval:org.mitre.oval:def:12490Denial of service via FTP status request
oval:org.mitre.oval:def:46DEPRECATED: IIS Help File Search Cross-site Scripting
oval:org.mitre.oval:def:12356Cross-site Scripting in IIS Help File search facility
oval:org.mitre.oval:def:58DEPRECATED: Windows NT IIS HTTP Redirect Error Message Cross-site Scripting
oval:org.mitre.oval:def:210DEPRECATED: Windows 2000 IIS HTTP Redirect Error Message Cross-site Scripting
oval:org.mitre.oval:def:12346Cross-site Scripting in Redirect Response message
oval:org.mitre.oval:def:25DEPRECATED: Windows 2000 IIS Chunked Encoding Buffer Overflow
oval:org.mitre.oval:def:16DEPRECATED: Windows NT IIS Chunked Encoding Buffer Overflow
oval:org.mitre.oval:def:12501Buffer overrun in Chunked Encoding mechanism

Open Source Vulnerability Database (OSVDB)

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
idDescription
59892Microsoft IIS Malformed Host Header Remote DoS
59621Microsoft IIS CodeBrws.asp Off-By-One File Check Bypass Source Disclosure
59561Microsoft IIS CodeBrws.asp Encoded Traversal Arbitrary File Source Disclosure
43451Microsoft IIS HTTP Request Smuggling
41456Microsoft IIS File Change Handling Local Privilege Escalation
Hide | Show 20 More...
idDescription
35962Microsoft Windows XP Registry QHEADLES Permission Weakness
28260Microsoft IIS FrontPage Server Extensions (FPSE) shtml.exe Path Disclosure
27152Microsoft Windows IIS ASP Page Processing Overflow
27087Microsoft IIS SMTP Encapsulated SMTP Address Open Relay
21557ColdFusion MX Error Message XSS
21537Microsoft IIS Log File Permission Weakness Remote Modification
18926Microsoft IIS SERVER_NAME Variable Spoofing Filter Bypass
17124Microsoft IIS Malformed WebDAV Request DoS
17123Microsoft IIS Multiple Unspecified Admin Pages XSS
17122Microsoft IIS Permission Weakness .COM File Upload
14229Microsoft IIS asp.dll Scripting.FileSystemObject Malformed Program DoS
13985Microsoft IIS Malformed HTTP Request Log Entry Spoofing
13761Microsoft Exchange 2000 Malformed URL Request DoS
13760Microsoft IIS Malformed URL Request DoS
13478Microsoft MS01-014 / MS01-016 Patch Memory Leak DoS
13439Microsoft IIS HTTP Request Malformed Content-Length DoS
13434Microsoft Windows Distributed Transaction Coordinator (DTC) Malformed Input DoS
13433Microsoft IIS WebDAV MKCOL Method Location Server Header Internal IP Disclosure
13432Microsoft IIS WebDAV WRITE Location Server Header Internal IP Disclosure
13431Microsoft IIS WebDAV Malformed PROPFIND Request Internal IP Disclosure

Metasploit Exploits

idDescription
2001-05-15Microsoft IIS/PWS CGI Filename Double Decode Command Execution