IIS 4.0 allows local users to bypass the User cannot change password policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_nt | Microsoft | 4.0 (including) | 4.0 (including) |
Windows_nt | Microsoft | 4.0-sp1 (including) | 4.0-sp1 (including) |
Windows_nt | Microsoft | 4.0-sp2 (including) | 4.0-sp2 (including) |
Windows_nt | Microsoft | 4.0-sp3 (including) | 4.0-sp3 (including) |
Windows_nt | Microsoft | 4.0-sp4 (including) | 4.0-sp4 (including) |
Windows_nt | Microsoft | 4.0-sp5 (including) | 4.0-sp5 (including) |
Windows_nt | Microsoft | 4.0-sp6 (including) | 4.0-sp6 (including) |
Windows_nt | Microsoft | 4.0-sp6a (including) | 4.0-sp6a (including) |