PT-2002-1160 · Microsoft · Iis
Published
2002-04-22
·
Updated
2018-10-30
·
CVE-2002-0071
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Information Server (IIS) versions 4.0 through 5.0
Description
A buffer overflow issue exists in the ism.dll ISAPI extension, which implements HTR scripting. This allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.
Recommendations
For IIS versions 4.0 through 5.0, consider disabling the ism.dll ISAPI extension as a temporary workaround until a patch is available. Restrict access to HTR scripting to minimize the risk of exploitation. Avoid using long variable names in HTR requests until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iis