PT-2008-5562 · Microsoft · Internet Information Services

Published

2008-09-29

·

Updated

2024-08-07

·

CVE-2008-4301

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Information Services (IIS) (affected versions not specified)
Description: A certain ActiveX control in iisext.dll allows remote attackers to set a password via a string argument to the SetPassword method. However, this issue could not be reproduced by a reliable third party, and the original researcher is considered unreliable, making the original disclosure probably erroneous.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2008-4301

Affected Products

Internet Information Services