PT-2014-2195 · Microsoft · Internet Information Services
Yuange
·
Published
2014-04-23
·
Updated
2020-11-23
·
CVE-2011-5279
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Information Services (IIS) versions 4.x through 5.x
Description
The issue allows remote attackers to modify arbitrary uppercase environment variables via a newline character in an HTTP header. This is due to a CRLF injection vulnerability in the CGI implementation.
Recommendations
For Microsoft Internet Information Services (IIS) versions 4.x through 5.x, consider restricting access to CGI implementations until a patch is available. As a temporary workaround, avoid using newline characters in HTTP headers to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Information Services