Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-1899 | First vendor Publication | 2010-09-15 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1899 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:7127 | |||
Oval ID: | oval:org.mitre.oval:def:7127 | ||
Title: | IIS Repeated Parameter Request Denial of Service Vulnerability | ||
Description: | Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-1899 | Version: | 8 |
Platform(s): | Microsoft Windows XP Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 | Product(s): | Microsoft Internet Information Server (IIS) 5.1 Microsoft Internet Information Server (IIS) 6.0 Microsoft Internet Information Server (IIS) 7.0 Microsoft Internet Information Server (IIS) 7.5 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 |
ExploitDB Exploits
id | Description |
---|---|
2010-07-02 | Microsoft Internet Information Services (IIS) 5 Authentication Bypass Vulnera... |
OpenVAS Exploits
Date | Description |
---|---|
2010-10-08 | Name : Microsoft IIS ASP Stack Based Buffer Overflow Vulnerability File : nvt/gb_ms_iis_bof_vuln.nasl |
2010-09-15 | Name : Microsoft Internet Information Services Remote Code Execution Vulnerabilities... File : nvt/secpod_ms10-065.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
67978 | Microsoft IIS Repeated Parameter Request Unspecified Remote DoS Microsoft IIS contains a flaw that is due to a stack overflow error in the script processing code when handling repeated parameter requests. This can be exploited to crash the service via specially crafted requests to hosted ASP scripts, which write parameters from the request in the response. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2010-09-16 | IAVM : 2010-A-0120 - Multiple Vulnerabilities in Microsoft Internet Information Services (IIS) Severity : Category I - VMSKEY : V0025353 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows IIS FastCGI request header buffer overflow attempt RuleID : 24380 - Revision : 9 - Type : SERVER-IIS |
2014-01-10 | Microsoft Windows IIS FastCGI request header buffer overflow attempt RuleID : 24379 - Revision : 14 - Type : SERVER-IIS |
2014-01-10 | Microsoft Windows IIS stack exhaustion DoS attempt RuleID : 24276 - Revision : 5 - Type : SERVER-IIS |
2014-01-10 | Microsoft Windows IIS stack exhaustion DoS attempt RuleID : 24275 - Revision : 7 - Type : SERVER-IIS |
2014-01-10 | Microsoft Windows IIS stack exhaustion DoS attempt RuleID : 24274 - Revision : 7 - Type : SERVER-IIS |
2014-01-10 | generic web server hashing collision attack RuleID : 20825 - Revision : 11 - Type : SERVER-WEBAPP |
2014-01-10 | Microsoft Windows IIS stack exhaustion DoS attempt RuleID : 19192 - Revision : 13 - Type : SERVER-IIS |
2014-01-10 | Microsoft Windows IIS FastCGI request header buffer overflow attempt RuleID : 19183 - Revision : 13 - Type : SERVER-IIS |
2014-01-10 | Microsoft Windows IIS FastCGI heap overflow attempt RuleID : 17255 - Revision : 9 - Type : WEB-IIS |
2014-01-10 | Microsoft Windows IIS stack exhaustion DoS attempt RuleID : 17254 - Revision : 12 - Type : SERVER-IIS |
2014-01-10 | IIS 5.1 alternate data stream authentication bypass attempt RuleID : 17103 - Revision : 16 - Type : SERVER-IIS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-04-03 | Name : The remote web server may allow remote code execution. File : iis_7_pci.nasl - Type : ACT_GATHER_INFO |
2010-09-14 | Name : The remote web server may allow remote code execution. File : smb_nt_ms10-065.nasl - Type : ACT_GATHER_INFO |
2010-07-05 | Name : The remote web server is affected by an authentication bypass vulnerability. File : iis_alternate_data_stream_authentication_bypass.nasl - Type : ACT_ATTACK |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:07:34 |
|
2024-11-28 12:22:00 |
|
2024-08-02 12:13:45 |
|
2024-08-02 01:03:43 |
|
2024-02-02 01:13:21 |
|
2024-02-01 12:03:39 |
|
2023-09-05 12:12:25 |
|
2023-09-05 01:03:30 |
|
2023-09-02 12:12:28 |
|
2023-09-02 01:03:32 |
|
2023-08-12 12:14:49 |
|
2023-08-12 01:03:32 |
|
2023-08-11 12:12:31 |
|
2023-08-11 01:03:40 |
|
2023-08-06 12:12:03 |
|
2023-08-06 01:03:34 |
|
2023-08-04 12:12:08 |
|
2023-08-04 01:03:35 |
|
2023-07-14 12:12:04 |
|
2023-07-14 01:03:33 |
|
2023-03-29 01:13:49 |
|
2023-03-28 12:03:39 |
|
2022-10-11 12:10:46 |
|
2022-10-11 01:03:21 |
|
2021-05-04 12:11:36 |
|
2021-04-22 01:12:13 |
|
2021-02-06 09:22:44 |
|
2021-02-05 21:23:14 |
|
2020-11-24 00:22:46 |
|
2020-05-23 13:16:55 |
|
2020-05-23 00:25:50 |
|
2019-07-06 00:19:19 |
|
2019-07-04 12:03:02 |
|
2018-10-13 00:22:57 |
|
2017-09-19 09:23:48 |
|
2016-04-26 19:49:27 |
|
2016-03-07 05:24:53 |
|
2016-03-07 00:23:38 |
|
2014-02-17 10:55:34 |
|
2014-01-19 21:26:52 |
|
2013-11-11 12:38:47 |
|
2013-05-10 23:25:13 |
|