A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."
References
Configurations
History
20 Nov 2024, 23:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.ciac.org/ciac/bulletins/n-011.shtml - | |
References | () http://www.iss.net/security_center/static/10504.php - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/6068 - | |
References | () http://www.securityfocus.com/bid/6071 - | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A931 - |
Information
Published : 2002-11-12 05:00
Updated : 2024-11-20 23:40
NVD link : CVE-2002-1180
Mitre link : CVE-2002-1180
CVE.ORG link : CVE-2002-1180
JSON object : View
Products Affected
microsoft
- internet_information_services
CWE