Vulnerability Name: | CVE-2010-1899 (CCN-61511) | ||||||||
Assigned: | 2010-09-14 | ||||||||
Published: | 2010-09-14 | ||||||||
Updated: | 2021-02-05 | ||||||||
Summary: | Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability." Per: http://www.microsoft.com/technet/security/Bulletin/MS10-065.mspx 'ASP pages are prohibited by default on IIS 6.0. - The vulnerability is only exploitable when the ASP script writes parameters from the request in the response.' | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
6.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-1899 Source: CCN Type: SA41399 Microsoft IIS Repeated Parameter Request Denial of Service Source: CCN Type: Microsoft Security Bulletin MS10-065 Vulnerabilities in Microsoft Internet Information Services (IIS) Could Allow Remote Code Execution (2267960) Source: CCN Type: BID-43140 Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability Source: MS Type: UNKNOWN MS10-065 Source: XF Type: UNKNOWN ms-iis-repeated-post-dos(61511) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:7127 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [10-01-2010] | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |