CVE Vulnerabilities

CVE-2002-1180

Published: Nov 12, 2002 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka Script Source Access Vulnerability.

Affected Software

Name Vendor Start Version End Version
Internet_information_services Microsoft 5.0 (including) 5.0 (including)

References