5
CVSSv2

CVE-2003-1566

Published: 15/01/2009 Updated: 08/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote malicious users to obtain sensitive information without detection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet information services 5.0

Exploits

source: wwwsecurityfocuscom/bid/9313/info A vulnerability has been reported to affect Microsoft IIS It has been reported that IIS fails to log HTTP TRACK calls made to the affected server A remote attacker may exploit this condition in order to enumerate server banners TRACK / HTTP/10 [\r\r] ...