Description
Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute arbitrary code after connecting a data stream to a device COM port; via requests for a URI containing a '/' immediately before and after the name of a DOS device, as demonstrated by the /AUX/.aspx URI, which bypasses a blacklist for DOS device requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T13:57:54.462Z
Reserved: 2007-05-29T00:00:00.000Z
Link: CVE-2007-2897
No data.
Status : Deferred
Published: 2007-05-30T10:30:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-2897
No data.
OpenCVE Enrichment
No data.
Weaknesses