Microsoft / Site Server
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2002-2081 | cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetUR… | MEDIUM | 5.0 | Jul 14, 2005 |
| CVE-2002-2073 | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary we… | MEDIUM | 4.3 | Jul 14, 2005 |
| CVE-2002-1769 | Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "L… | HIGH | 7.5 | Jun 21, 2005 |
| CVE-1999-1520 | A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which expose… | MEDIUM | 5.0 | Sep 1, 2004 |
| CVE-1999-1246 | Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure defaul… | HIGH | 7.5 | Mar 9, 2002 |
| CVE-1999-1451 | The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files. | MEDIUM | 5.0 | Sep 12, 2001 |
| CVE-2000-0246 | IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the… | MEDIUM | 5.0 | Jun 2, 2000 |
| CVE-1999-1011 | The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote a… | HIGH | 10.0 | Jun 2, 2000 |
| CVE-2000-0024 | IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka… | MEDIUM | 6.4 | Apr 25, 2000 |
| CVE-2000-0161 | Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands. | HIGH | 7.5 | Mar 22, 2000 |
| CVE-2000-0025 | IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such… | MEDIUM | 5.0 | Mar 22, 2000 |
| CVE-1999-0910 | Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used… | MEDIUM | 5.0 | Feb 4, 2000 |
| CVE-1999-0360 | MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely. | HIGH | 7.2 | Feb 4, 2000 |
| CVE-1999-0867 | Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | MEDIUM | 5.0 | Jan 4, 2000 |
| CVE-1999-0861 | Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | LOW | 2.6 | Jan 4, 2000 |
Showing 1 to 15 of 15 CVEs