Vulnerability Name: | CVE-2002-1180 (CCN-10504) | ||||||||
Assigned: | 2002-10-30 | ||||||||
Published: | 2002-10-30 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability." | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2002-1180 Source: CCN Type: CIAC Information Bulletin N-011 Cumulative Patch for Internet Information Service Source: CIAC Type: UNKNOWN N-011 Source: XF Type: Patch, Vendor Advisory iis-script-source-access-bypass(10504) Source: CCN Type: Microsoft Security Bulletin MS02-062 Cumulative Patch for Internet Information Service (Q327696) Source: CCN Type: Microsoft Security Bulletin MS03-018 Cumulative Patch for Internet Information Service (811114) Source: BID Type: UNKNOWN 6068 Source: CCN Type: BID-6068 Multiple Microsoft IIS Vulnerabilities Source: BID Type: UNKNOWN 6071 Source: CCN Type: BID-6071 Microsoft IIS Script Source Access File Upload Vulnerability Source: MS Type: UNKNOWN MS02-062 Source: XF Type: UNKNOWN iis-script-source-access-bypass(10504) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:931 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |