What are some known vulnerabilities with Microsoft Internet Information Server?
There are a few, and they are deadly. If a site is running Microsoft Internet Information Server v1.0, the default installation leaves the server wide open. The example hack illustrated here assumes that the CGI directory is /scripts, there are no files called pfieffer.bat or pfieffer.cmd in the scripts directory, and the web server links .bat and .cmd files to cmd.exe.