PT-2009-1134 · Microsoft · Internet Information Services

Parcifal Aertssen

·

Published

2009-01-15

·

Updated

2017-08-08

·

CVE-2003-1566

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Internet Information Services (IIS) version 5.0
Description The issue allows remote attackers to obtain sensitive information without detection because it does not log requests that use the TRACK method.
Recommendations For Microsoft Internet Information Services (IIS) version 5.0, consider disabling the TRACK method to prevent exploitation until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-1566

Affected Products

Internet Information Services