Vulnerability Name: | CVE-2000-0886 (CCN-5470) | ||||||||
Assigned: | 2000-11-06 | ||||||||
Published: | 2000-11-06 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2000-0886 Source: CCN Type: CIAC Information Bulletin L-018 Microsoft "Web Server File Request Parsing" Source: CCN Type: Microsoft Security Bulletin MS00-086 FAQ Microsoft Security Bulletin (MS00-086): Frequently Asked Questions Source: CCN Type: Microsoft Security Bulletin MS00-086 Patch Available for 'Web Server File Request Parsing' Vulnerability Source: CCN Type: Microsoft Security Bulletin MS01-041 Malformed RPC Request Can Cause Service Failure Source: CCN Type: Microsoft Security Bulletin MS02-001 Trusting Domains Do Not Verify Domain Membership of SIDs in Authorization Data Source: CCN Type: Microsoft Security Bulletin MS02-018 Cumulative Patch for Internet Information Services (Q319733) Source: CCN Type: Microsoft Security Bulletin MS02-062 Cumulative Patch for Internet Information Service (Q327696) Source: CCN Type: Microsoft Security Bulletin MS03-018 Cumulative Patch for Internet Information Service (811114) Source: CCN Type: National Infrastructure Protection Center Advisory 01-023 Update to NIPC Advisory 01-003 "E-Commerce Vulnerabilities" Source: CCN Type: NSFOCUS Security Advisory SA2000-07 Microsoft IIS 4.0/5.0 CGI File Name Inspection Vulnerability Source: CCN Type: OSVDB ID: 525 Microsoft IIS Webserver Invalid Filename Request Arbitrary Command Execution Source: BID Type: UNKNOWN 1912 Source: CCN Type: BID-1912 Microsoft IIS Executable File Parsing Vulnerability Source: BUGTRAQ Type: Vendor Advisory 20001107 NSFOCUS SA2000-07 : Microsoft IIS 4.0/5.0 CGI File Name Inspection Vulnerability Source: MS Type: UNKNOWN MS00-086 Source: XF Type: UNKNOWN iis-invalid-filename-passing(5470) Source: XF Type: UNKNOWN iis-invalid-filename-passing(5470) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:191 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |