May 16, 2001

Yet another IIS exploit reported

Author: JT Smith

The Register: "It's been a rough two weeks for IIS security. On 1 May it was our solemn duty to
report the IIS .printer ISAPI vulnerability; on 8 May we reported the sadmind/IIS
worm; and today we have to inform you of a brand new stuff-up affecting IIS 4.0
and 5.0, handily exploited with a simple Unicode trick."


