CVE-1999-1538

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:31

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=91638375309890&w=2 - () http://marc.info/?l=bugtraq&m=91638375309890&w=2 -
References () http://marc.info/?l=ntbugtraq&m=91632724913080&w=2 - () http://marc.info/?l=ntbugtraq&m=91632724913080&w=2 -
References () http://www.securityfocus.com/bid/189 - Exploit () http://www.securityfocus.com/bid/189 - Exploit

Information

Published : 1999-01-14 05:00

Updated : 2024-11-20 23:31


NVD link : CVE-1999-1538

Mitre link : CVE-1999-1538

CVE.ORG link : CVE-1999-1538


JSON object : View

Products Affected

microsoft

  • internet_information_server