Advertisement
Promo

Become a member of the ZDNet UK community

Resources Downloads

Download Now

Microsoft "Malformed Web Form Submission" Vulnerability Patch (IIS 5.0) MS00-100


License Free
Requirements Windows 2000
Downloads 191 Limitations None
Publisher Microsoft File Size 576k
Date added 10 Jan 2001 Check your speed

This patch eliminates a security vulnerability in a component that ships as part of Microsoft Internet Information Server. The vulnerability could potentially allow an attacker to prevent an affected Web server from providing useful service.

The FrontPage Server Extensions (FPSE) ship with and are installed by default as part of IIS 4.0 and 5.0. The most familiar FPSE functions allow Web site and content management; however, FPSE also provides browse-time support functions. Among the functions included in the latter category are ones that help process Web forms that have been submitted by a user. A vulnerability exists in one of these functions. If a malicious user levied a specially-malformed form submission to an affected server, it would cause the IIS service to fail. The vulnerability does not provide the opportunity to misuse any of the FPSE administrative or content management functions.

To resume normal operation on an IIS 4.0 server, the operator would need to restart the service. In contrast, if an IIS 5.0 server were attacked via this vulnerability, the IIS service would, by default, automatically restart almost immediately. Although any Web sessions that were in progress at the time of the attack would be lost, the server would be able to accept new connections as soon as the service was restarted. FPSE is installed by default as part of IIS 4.0 and 5.0, but, in keeping with best practices, Microsoft recommends that they be disabled if not needed.

Download Now

Did you find this download useful?
24 out of 49 users found this download useful


People who downloaded this software also downloaded...

AdArmor 3.0.42

Eliminate ads and stop unsuitable content.

More info +


Hitware Popup Killer Lite 3.1.1

Get rid of annoying pop-ups appearing as browser windows and Messenger Service dialogs.

More info +


Access Manager 9.1

Control Internet and computer usage and restrict access to Windows' key features.

More info +


Advanced Internet Kiosk 6.22

Create Internet kiosks, public access PCs, or in-store terminals.

More info +


abylon LOGON 7.3

Lock and log out your computer when you pull your smart card or USB stick.

More info +


Ultra Ad Killer 1.31

Block various kinds of pop-ups and erase the tracks of your Internet activities.

More info +


Pop-Up No-No 2.1

Block pop-up, pop-under, multimedia Flash, and messenger service ads.

More info +


Anti-AD Guard PRO 2.1 build 2127

Filter and stop browsers from loading ads.

More info +


Panda Global Protection 2010 3.01

Surf the Internet without danger of being infected.

More info +


Anti-AD Guard 2.1 build 2125

Filter and stop browsers from loading advertisements.

More info +


Broadband Deals? Powered by Top 10 Broadband

150+ broadband packages

Compare 30+ mobile broadband deals

Mobile Broadband »

Download

Trend Micro Worry-Free Business Security Advanced

Trend Micro™ Worry-Free™ Business Security Advanced and Standard 6. #1 for Small Business Security

  • Downloads: 1,249
  • Requirements: Processor: Intel™ Pentium™ or AMD™. RAM: 256MB-1GB (operating system dependant). Disk space: 350MB. Web Browser: Microsoft™ Internet Explorer 6.0 or 7.0.
  • License:
  • Publisher:
  • Size: 0

Download Now

Google Chrome Special Report

All roads lead to Chrome

All roads lead to Chrome

Comment With its new browser, Google has finally taken its gaudy, chrome-plated, futuristic ray gun and pointed it straight at Microsoft's head

More Special Reports


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters