CVE-2005-2678
published 2005-08-23CVE-2005-2678: Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with…
PriorityP270medium5CVSS 2.0
AVNACLAuNCPINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
39.81%
98.5th percentile
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_information_server | — | — |
| microsoft | internet_information_services | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8hvh-6q2x-vwrc: Microsoft IIS 5
ghsa_unreviewed·2022-05-01
CVE-2005-2678 [MEDIUM] GHSA-8hvh-6q2x-vwrc: Microsoft IIS 5
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
VulnCheck
Microsoft IIS SERVER_NAME Variable Bypass Vulnerability
vulncheck·2005·CVSS 5.0
CVE-2005-2678 [MEDIUM] Microsoft IIS SERVER_NAME Variable Bypass Vulnerability
Microsoft IIS SERVER_NAME Variable Bypass Vulnerability
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
Affected: Microsoft Internet Information Services (IIS)
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.bleepingcomputer.com/news/security/linux-and-windows-servers-targeted-with-rubyminer-malware/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ingehenriksen.blogspot.com/2005/08/remote-iis-5x-and-iis-60-server-name.htmlhttp://marc.info/?l=bugtraq&m=112474727903399&w=2http://secunia.com/advisories/16548http://www.vupen.com/english/advisories/2005/1503http://ingehenriksen.blogspot.com/2005/08/remote-iis-5x-and-iis-60-server-name.htmlhttp://marc.info/?l=bugtraq&m=112474727903399&w=2http://secunia.com/advisories/16548http://www.vupen.com/english/advisories/2005/1503
2005-08-23
Published
Exploited in the wild