vendor:
IIS 4.0
by:
stinko
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: IIS 4.0
Affected Version From: IIS 4.0 SP3
Affected Version To: IIS 4.0 SP5
Patch Exists: YES
Related CWE: CVE-1999-0874
CPE: a:microsoft:iis:4.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows NT 4.0
1999
Microsoft IIS 4.0 .HTR Path Overflow
This exploits a buffer overflow in the ISAPI ISM.DLL used to process HTR scripting in IIS 4.0. This module works against Windows NT 4 Service Packs 3, 4, and 5. The server will continue to process requests until the payload being executed has exited.
Mitigation:
Upgrade to the latest version of IIS 4.0