ID

VAR-199905-0029


CVE

CVE-1999-0737


TITLE

Microsoft IIS 4.0 showcode.asp Example script to see arbitrary file vulnerabilities (MS99-013)

Trust: 0.6

sources: CNNVD: CNNVD-199905-015

DESCRIPTION

The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. IIS is prone to a remote security vulnerability. Attackers can exploit this issue to perform unauthorized actions. This may aid in further attacks

Trust: 1.17

sources: NVD: CVE-1999-0737 // BID: 88098

AFFECTED PRODUCTS

vendor:microsoftmodel:internet information serverscope:eqversion:4.0

Trust: 1.6

vendor:microsoftmodel:iisscope:eqversion:4.0

Trust: 0.3

sources: BID: 88098 // CNNVD: CNNVD-199905-015 // NVD: CVE-1999-0737

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-1999-0737
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-199905-015
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-1999-0737
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-199905-015 // NVD: CVE-1999-0737

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-1999-0737

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-199905-015

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-199905-015

EXTERNAL IDS

db:NVDid:CVE-1999-0737

Trust: 1.9

db:MSid:MS99-013

Trust: 0.6

db:NSFOCUSid:3400

Trust: 0.6

db:CNNVDid:CNNVD-199905-015

Trust: 0.6

db:BIDid:88098

Trust: 0.3

sources: BID: 88098 // CNNVD: CNNVD-199905-015 // NVD: CVE-1999-0737

REFERENCES

url:https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013

Trust: 1.0

url:http://www.microsoft.com/technet/security/bulletin/ms99-013.asp

Trust: 0.9

url:http://www.nsfocus.net/vulndb/3400

Trust: 0.6

sources: BID: 88098 // CNNVD: CNNVD-199905-015 // NVD: CVE-1999-0737

CREDITS

Parcens

Trust: 0.6

sources: CNNVD: CNNVD-199905-015

SOURCES

db:BIDid:88098
db:CNNVDid:CNNVD-199905-015
db:NVDid:CVE-1999-0737

LAST UPDATE DATE

2024-08-14T14:01:04.960000+00:00


SOURCES UPDATE DATE

db:BIDid:88098date:1999-05-07T00:00:00
db:CNNVDid:CNNVD-199905-015date:2012-05-07T00:00:00
db:NVDid:CVE-1999-0737date:2018-10-12T21:29:11.310

SOURCES RELEASE DATE

db:BIDid:88098date:1999-05-07T00:00:00
db:CNNVDid:CNNVD-199905-015date:1999-05-07T00:00:00
db:NVDid:CVE-1999-0737date:1999-05-07T04:00:00