imPC@ndo IT

Tracker / CVE-2000-0886

CVE-2000-0886

High 7.5

IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.

Affected products and versions

microsoft internet_information_server
microsoft internet_information_services

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References