iis.isapi.htr.txt...

- AV AC AU C I A
发布: 2002-04-11
修订: 2025-04-13

Microsoft IIS 4.0 and 5.0 contains a buffer overrun condition in the isapi extension that handles .htr extensions that allows attackers to crash the service and/or execute arbitrary code on the server. A flaw in ism.dll which handles files with the .htr extension is the cause of this vulnerability. Microsoft advisory on this vulnerability here.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息