CVE-2002-1180 Information

Share on:

Description

A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files which allows attackers with only write permissions to upload malicious .COM files aka \Script Source Access Vulnerability.\

Reference

http://www.ciac.org/ciac/bulletins/n-011.shtml http://www.iss.net/security_center/static/10504.php http://www.securityfocus.com/bid/6068 http://www.securityfocus.com/bid/6071 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A931