CVE-2003-0718

Internet Information Services 5.0-6.0 - Denial of Service via WebDAV PROPFIND XML Attribute Flood

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0718. PoCs published by Amit Klein.

AI-analyzed exploit summary This exploit targets a vulnerability in Microsoft IIS via a malformed PROPFIND request with excessive XML namespace declarations, causing a denial-of-service (DoS) condition. It leverages the CVE-2003-0718 vulnerability, which affects IIS 5.0 and 6.0.

Description

The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Amit Klein · perldoswindows
https://www.exploit-db.com/exploits/585

This exploit targets a vulnerability in Microsoft IIS via a malformed PROPFIND request with excessive XML namespace declarations, causing a denial-of-service (DoS) condition. It leverages the CVE-2003-0718 vulnerability, which affects IIS 5.0 and 6.0.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft IIS 5.0/6.0
No auth needed
Prerequisites: Network access to the target IIS server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4767
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17645
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17656
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1330
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=109762641822064&w=2
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1427

Scores

EPSS 0.8791
EPSS Percentile 99.7%

Details

Status published
Products (2)
microsoft/internet_information_server 6.0
microsoft/internet_information_services 5.0
Published Nov 03, 2004
Tracked Since Feb 18, 2026