20030528 Internet Information Services 5.0 Denial of servicemailing list
http://archives.neohapsis.com/archives/bugtraq/2003-05/0308.html CVE-2003-0226
Microsoft IIS 5.0 - WebDAV PROPFIND / SEARCH Method Denial of Service
Record summary
CVE-2003-0226 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits.
Description
Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMicrosoft IIS 5.0 - WebDAV PROPFIND / SEARCH Method Denial of ServiceExploitDB exploitby Neo1Not analyzed1 file
ExploitDBMicrosoft IIS 5.0 < 5.1 - Remote Denial of ServiceExploitDB exploitby ShachankNot analyzed1 file
References
720030529 IIS WEBDAV Denial of Service attacksmailing list
http://marc.info/?l=bugtraq&m=105427362724860&w=2 20030528 Internet Information Services 5.0 Denial of servicemailing list
http://marc.info/?l=ntbugtraq&m=105421243732552&w=2 spidynamics.com
http://www.spidynamics.com/iis_alert.html MS03-018Vendor advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0226 oval:org.mitre.oval:def:933vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A933