PT-2001-1710 · Microsoft · Iis+2
Publicado
2001-07-21
·
Atualizado
2025-03-14
·
CVE-2001-0500
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Index Server 2.0 and Indexing Service 2000 in IIS versions prior to 6.0
Description:
A buffer overflow issue exists in the ISAPI extension idq.dll, allowing remote attackers to execute arbitrary commands. This is achieved by providing a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files, such as default.ida. This issue has been commonly exploited.
Recommendations:
For Index Server 2.0 and Indexing Service 2000 in IIS versions prior to 6.0, consider disabling the idq.dll ISAPI extension as a temporary workaround until a patch is available. Restrict access to .ida and .idq files to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iis
Index Server 2.0
Indexing Service 2000