CVE-2005-4360

Scores

EPSS

0.771medium77.1%
0%20%40%60%80%100%

Percentile: 77.1%

CVSS

7.8high2.0
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 2.0
7.8

Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N

Description

The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to “.dll” followed by arguments such as “~0” through “~9”, which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as demonstrated using “/_vti_bin/.dll/*/~0”. NOTE: the consequence was originally believed to be only a denial of service (application crash and reboot).

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-252

Exploits

Exploit ID: 1376

Source: exploitdb

URL: https://www.exploit-db.com/exploits/1376

Exploit ID: 1377

Source: exploitdb

URL: https://www.exploit-db.com/exploits/1377

Vulnerable Software (1)

Type: Configuration

Vendor: microsoft

Product: internet_information_services

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:internet_information_services:5.1:*:*:*:*:*:*:*",          "vulnerable": true        }      ],    ...

Source: nvd