CVE-2002-1180

A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:40

Type Values Removed Values Added
References () http://www.ciac.org/ciac/bulletins/n-011.shtml - () http://www.ciac.org/ciac/bulletins/n-011.shtml -
References () http://www.iss.net/security_center/static/10504.php - Patch, Vendor Advisory () http://www.iss.net/security_center/static/10504.php - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/6068 - () http://www.securityfocus.com/bid/6068 -
References () http://www.securityfocus.com/bid/6071 - () http://www.securityfocus.com/bid/6071 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A931 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A931 -

Information

Published : 2002-11-12 05:00

Updated : 2024-11-20 23:40


NVD link : CVE-2002-1180

Mitre link : CVE-2002-1180

CVE.ORG link : CVE-2002-1180


JSON object : View

Products Affected

microsoft

  • internet_information_services