CVE-2005-2089

Microsoft Internet Information Services - HTTP Request Smuggling

Title source: rule

Description

Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

Scores

EPSS 0.3563
EPSS Percentile 97.0%

Classification

CWE
CWE-444
Status draft

Affected Products (2)

microsoft/internet_information_services
microsoft/internet_information_services

Timeline

Published Jul 05, 2005
Tracked Since Feb 18, 2026