CVE-1999-0233

Internet Information Services 1.0 - Remote Command Execution via .bat or .cmd Files

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0233. PoCs published by anonymous.

AI-analyzed exploit summary This is a writeup describing a remote command execution vulnerability in older web servers (IIS 1.0, Netscape Commerce Server 1.0, etc.) where batch files executed via CGI can be manipulated to run arbitrary commands using the ampersand (&) symbol. The vulnerability allows command injection with web server privileges.

Description

IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.

Exploits (1)

exploitdb WRITEUP VERIFIED
by anonymous · textremotewindows
https://www.exploit-db.com/exploits/20445

This is a writeup describing a remote command execution vulnerability in older web servers (IIS 1.0, Netscape Commerce Server 1.0, etc.) where batch files executed via CGI can be manipulated to run arbitrary commands using the ampersand (&) symbol. The vulnerability allows command injection with web server privileges.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft IIS 1.0, Netscape Commerce Server 1.0, O'Reilly WebSite Professional 1.1b
No auth needed
Prerequisites: CGI-enabled web server with .bat or .cmd file execution allowed
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ148188
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ155056

Scores

EPSS 0.1627
EPSS Percentile 96.6%

Details

Status published
Products (1)
microsoft/internet_information_services 1.0
Published Feb 25, 1996
Tracked Since Feb 18, 2026