← Volver a CVEs
CVE-2005-2678
N/ADescripcion
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado8/23/2005
Ultima modificacion4/16/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
microsoft:internet_information_servermicrosoft:internet_information_services
Referencias
http://marc.info/?l=bugtraq&m=112474727903399&w=2(cve@mitre.org)
http://secunia.com/advisories/16548(cve@mitre.org)
http://www.vupen.com/english/advisories/2005/1503(cve@mitre.org)
http://ingehenriksen.blogspot.com/2005/08/remote-iis-5x-and-iis-60-server-name.html(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=112474727903399&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/16548(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2005/1503(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.