Total vulnerabilities in the database
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.
Software | From | Fixed in |
---|---|---|
microsoft / windows_nt | 4.0 | 4.0.x |
microsoft / windows_nt | 4.0-sp1 | 4.0-sp1.x |
microsoft / windows_nt | 4.0-sp3 | 4.0-sp3.x |
microsoft / windows_nt | 4.0-sp6 | 4.0-sp6.x |
microsoft / windows_nt | 4.0-sp4 | 4.0-sp4.x |
microsoft / windows_nt | 4.0-sp6a | 4.0-sp6a.x |
microsoft / windows_nt | 4.0-sp2 | 4.0-sp2.x |
microsoft / windows_nt | 4.0-sp5 | 4.0-sp5.x |