CVE-1999-1538
LOW—CVSS v3
2.1CVSS v2
50.26%
EPSS (exploit probability)
—CWE
Description
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
Affected routers (0)
No routers currently mapped to this CVE in our database.