Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-1446
Description:Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
Test IDs: 1.3.6.1.4.1.25623.1.0.900052  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-1446
BugTraq ID: 31682
http://www.securityfocus.com/bid/31682
Cert/CC Advisory: TA08-288A
http://www.us-cert.gov/cas/techalerts/TA08-288A.html
CERT/CC vulnerability note: VU#793233
http://www.kb.cert.org/vuls/id/793233
HPdes Security Advisory: HPSBST02379
http://marc.info/?l=bugtraq&m=122479227205998&w=2
HPdes Security Advisory: SSRT080143
http://marc.info/?l=bugtraq&m=122479227205998&w=2
Microsoft Security Bulletin: MS08-062
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-062
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5764
http://www.securitytracker.com/id?1021048
http://secunia.com/advisories/32248
http://www.vupen.com/english/advisories/2008/2813
XForce ISS Database: win-ipp-service-code-execution(45545)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45545
XForce ISS Database: win-ms08kb953155-update(45548)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45548




© 1998-2025 E-Soft Inc. All rights reserved.