Vulnerabilities > CVE-2003-1566 - Configuration vulnerability in Microsoft Internet Information Services 5.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
microsoft
CWE-16
exploit available

Summary

Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionMicrosoft IIS 5.0 Failure To Log Undocumented TRACK Requests Vulnerability. CVE-2003-1566. Remote exploit for windows platform
idEDB-ID:23490
last seen2016-02-02
modified2003-12-29
published2003-12-29
reporterParcifal Aertssen
sourcehttps://www.exploit-db.com/download/23490/
titleMicrosoft IIS 5.0 Failure To Log Undocumented TRACK Requests Vulnerability