CVE-1999-0449: High severity microsoft internet information server vulnerability
The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft IIS ExAir sample sitefrom your environment.Remove or uninstall the ExAir sample site from the IIS server to eliminate the vulnerable sample scripts (advsearch.asp, query.asp, search.asp).
- Remove
Remove
Microsoft IIS (advsearch.asp, query.asp, search.asp)from your environment.Delete or move the advsearch.asp, query.asp, and search.asp files from the web root or any served directories to prevent direct requests to these scripts.
- Compensating control
If immediate removal is not possible, block or deny HTTP access to advsearch.asp, query.asp, and search.asp using IIS URL Authorization, request filtering, a web application firewall, or network ACL/firewall rules to prevent remote requests that could cause CPU consumption.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0449?
CVE-1999-0449 has a moderate severity rating due to its ability to cause denial of service through high CPU consumption.
How do I fix CVE-1999-0449?
To fix CVE-1999-0449, it is recommended to apply the latest patches and updates to Microsoft Internet Information Server 4.0.
What scripts are involved in CVE-1999-0449?
CVE-1999-0449 involves denial of service through the advsearch.asp, query.asp, and search.asp scripts.
Who is affected by CVE-1999-0449?
CVE-1999-0449 affects users and administrators of Microsoft Internet Information Server version 4.0.
What type of vulnerability is CVE-1999-0449?
CVE-1999-0449 is categorized as a denial of service vulnerability.