When IIS 2 or 3 is upgraded to IIS 4, ism.dll is...
Low severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Jan 14, 1999
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Jan 30, 2023
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
References