First published: Tue Nov 12 2002(Updated: )
A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1180 is classified as a medium severity vulnerability.
To fix CVE-2002-1180, you should update Internet Information Server to a version that has addressed this vulnerability.
CVE-2002-1180 can be exploited by attackers who have write permissions to upload and execute malicious .COM files.
CVE-2002-1180 specifically affects Microsoft Internet Information Services version 5.0.
A potential workaround for CVE-2002-1180 is to restrict write permissions on affected directories.