CVE-1999-1223

Internet Information Server 3.0 - Denial of Service via ASP Page URL with Excessive Forward Slashes

Title source: llm
STIX 2.1

Description

IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/3892
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/support/kb/articles/q187/5/03.asp

Scores

EPSS 0.2306
EPSS Percentile 97.5%

Details

Status published
Products (1)
microsoft/internet_information_server 3.0
Published Dec 31, 1999
Tracked Since Feb 18, 2026