Site Server Commerce
Microsoft · 8 CVEs
cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an…
Jul 14, 2005
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows…
Jul 14, 2005
Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword…
Jun 21, 2005
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, w…
Jun 2, 2000
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-p…
Apr 25, 2000
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual direct…
Mar 22, 2000
Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be…
Feb 4, 2000
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
Jan 4, 2000
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2002-2081 | cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetUR… | MEDIUM | 13.90% | Jul 14, 2005 |
| CVE-2002-2073 | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary we… | MEDIUM | 12.86% | Jul 14, 2005 |
| CVE-2002-1769 | Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "L… | HIGH | 11.70% | Jun 21, 2005 |
| CVE-2000-0246 | IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the… | MEDIUM | 79.98% | Jun 2, 2000 |
| CVE-2000-0024 | IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka… | MEDIUM | 12.22% | Apr 25, 2000 |
| CVE-2000-0025 | IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such… | MEDIUM | 34.85% | Mar 22, 2000 |
| CVE-1999-0910 | Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used… | MEDIUM | 5.78% | Feb 4, 2000 |
| CVE-1999-0861 | Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | LOW | 3.21% | Jan 4, 2000 |
Showing 1 to 8 of 8 CVEs