Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1899

Опубликовано: 15 сент. 2010
Источник: nvd
CVSS2: 4.3
EPSS Высокий

Описание

Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."

Комментарий

Per: http://www.microsoft.com/technet/security/Bulletin/MS10-065.mspx

'ASP pages are prohibited by default on IIS 6.0. - The vulnerability is only exploitable when the ASP script writes parameters from the request in the response.'

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:internet_information_server:6.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_information_services:7.5:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.85958
Высокий

4.3 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
больше 3 лет назад

Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."

EPSS

Процентиль: 99%
0.85958
Высокий

4.3 Medium

CVSS2

Дефекты

CWE-119