Remote Code Execution Vulnerability in Internet Information Services - MS08-006
|ID: oval:org.secpod.oval:def:2655||Date: (C)2011-11-02 (M)2018-05-28|
|Class: PATCH||Family: windows|
The host is missing an important security update according to Microsoft security bulletin, MS08-006. The update is required to fix remote code execution vulnerability. A flaw is present in Internet Information Services (IIS), which fails to handle input to ASP Web pages. Successful exploitation could allow an attacker to use an account with administrative privileges and more seriously impact than IIS servers.
|Microsoft Windows 2000|
|Microsoft Windows XP|
|Microsoft Internet Information Server (IIS) 5.1|
|Microsoft Internet Information Server (IIS) 6.0|