PT-2003-1445 · Microsoft · Internet Information Services

Mark Litchfield

·

Published

2003-05-30

·

Updated

2020-11-23

·

CVE-2003-0226

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Information Services (IIS) versions 5.0 and 5.1
Description: The issue allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method. This generates an error condition that is not properly handled.
Recommendations: For Microsoft Internet Information Services (IIS) version 5.0, consider restricting access to WebDAV requests as a temporary workaround until a patch is available. For Microsoft Internet Information Services (IIS) version 5.1, consider restricting access to WebDAV requests as a temporary workaround until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0226

Affected Products

Internet Information Services