PT-2002-1160 · Microsoft · Iis
Publicado
2002-04-22
·
Atualizado
2018-10-30
·
CVE-2002-0071
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Information Server (IIS) versions 4.0 through 5.0
Description
A buffer overflow issue exists in the ism.dll ISAPI extension, which implements HTR scripting. This allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.
Recommendations
For IIS versions 4.0 through 5.0, consider disabling the ism.dll ISAPI extension as a temporary workaround until a patch is available. Restrict access to HTR scripting to minimize the risk of exploitation. Avoid using long variable names in HTR requests until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iis