CVE-2008-4301
high · 10A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be reproduced by a reliable third party. In addition, the original researcher is unreliable. Therefore the original disclosure is probably erroneous
10
CVSS
17.1%
EPSS (exploit prob.)
97th
EPSS percentile
2008-09-29
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_information_services | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.attrition.org/pipermail/vim/2008-October/002081.html
- http://www.securityfocus.com/archive/1/496694/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45587
- http://www.attrition.org/pipermail/vim/2008-October/002081.html
- http://www.securityfocus.com/archive/1/496694/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45587
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-4301