This application requires Javascript for optimal performance.

ExAir.Search.ASP.Access

Alias(es)

IIS.ExAir.Search.ASP.Access

Release Date

Sep 11, 2006

Severity

low

Impact

Attackers can cause DoS on the victim system.

Description

It indicates a potential Denial-of-Service (DoS) vulnerability in Microsoft Internet Information Service (IIS) ExAir sample site.



There exists a vulnerability in IIS version 4.0 ExAir sample site pages that allows a remote attacker to consume all processing power on a target system by passing it a specially-crafted URL requests.

Affected Products

Any unprotected IIS 4.0 is vulnerable to the attack.

Recommended Actions

Apply appropriate patches from Microsoft and/or upgrade the system to the latest non-vulnerable version.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-1999-0449

Reference/s

http://www.securityfocus.com/bid/193 (BugTraq)

Reference: VID-12933