vendor:
IIS
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: IIS
Affected Version From: 4
Affected Version To: 5
Patch Exists: NO
Related CWE: CVE-2002-0392
CPE: a:microsoft:iis
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Microsoft IIS 4.0/5.0 Malformed File Extension Denial of Service Vulnerability
Sending a specially crafted URL containing malformed file extension information to Microsoft IIS 4.0/5.0 will consume CPU usage until it reaches 100% which will halt the program's services. Restarting the application or waiting until the URL is processed will be required in order to regain normal functionality.
Mitigation:
Restarting the application or waiting until the URL is processed will be required in order to regain normal functionality.