| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. |
| Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. |
| By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. |
| The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. |
| Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. |
| The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. |
| In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. |
| Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. |
| MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely. |
| A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. |
| IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. |
| NT users can gain debug-level access on a system process using the Sechole exploit. |
| Buffer overflow in NetMeeting allows denial of service and remote command execution. |
| Buffer overflow in Internet Explorer 4.0(1). |
| Bonk variation of teardrop IP fragmentation denial of service. |
| Buffer overflow in War FTP allows remote execution of commands. |
| IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
| IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |
| Denial of service in Windows NT IIS server using ..\.. |
| Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT. |