Vulnerabilities > CVE-2005-2678 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://ingehenriksen.blogspot.com/2005/08/remote-iis-5x-and-iis-60-server-name.html
- http://ingehenriksen.blogspot.com/2005/08/remote-iis-5x-and-iis-60-server-name.html
- http://marc.info/?l=bugtraq&m=112474727903399&w=2
- http://marc.info/?l=bugtraq&m=112474727903399&w=2
- http://secunia.com/advisories/16548
- http://secunia.com/advisories/16548
- http://www.vupen.com/english/advisories/2005/1503
- http://www.vupen.com/english/advisories/2005/1503