This script is Copyright (C) 2010-2015 Tenable Network Security, Inc.
The remote web server may allow remote code execution.
The version of IIS installed on the remote host has the following
- Sending a specially crafted request for an ASP page
on a website hosted by IIS can result in a denial of
- Sending a specially crafted HTTP request to an IIS
server with FastCGI enabled can result in remote
code execution. (CVE-2010-2730)
- Sending a specially crafted request to an IIS server
running on Windows XP can allow a remote attacker to
bypass the need to authenticate to access restricted
See also :
Microsoft has released a set of patches for IIS on Windows XP, 2003,
Vista, 2008, 7, and 2008 R2.
Risk factor :
Medium / CVSS Base Score : 6.8
CVSS Temporal Score : 5.6
Public Exploit Available : true
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 49223 ()
Bugtraq ID: 413144313843140
CVE ID: CVE-2010-1899CVE-2010-2730CVE-2010-2731
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.