First published: Fri Dec 31 1999(Updated: )
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-1999-1223 is classified as a denial of service vulnerability that can affect the availability of the IIS 3.0 server.
To fix CVE-1999-1223, you should update your software to a version of Internet Information Server that is not vulnerable and apply all security patches.
CVE-1999-1223 specifically affects Microsoft Internet Information Server 3.0.
Yes, CVE-1999-1223 can be exploited remotely by attackers sending specially crafted requests to the server.
The impact of CVE-1999-1223 is that it can lead to service disruptions, causing denial of service for users attempting to access web applications hosted on the affected server.