CVE-2005-2678
EXPLOITEDMicrosoft Internet Information Server 5.1 and 6 - Server Name Spoofing via Localhost URI
Title source: llmExploitation Summary
CVE-2005-2678 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
References (4)
Core 4
Core References
Various Sources x_refsource_misc
http://ingehenriksen.blogspot.com/2005/08/remote-iis-5x-and-iis-60-server-name.html
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1503
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/16548
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112474727903399&w=2
Scores
EPSS
0.3981
EPSS Percentile
98.5%
Details
VulnCheck KEV
2018-01-15
Status
published
Products (2)
microsoft/internet_information_server
6.0
microsoft/internet_information_services
5.0
Published
Aug 23, 2005
Tracked Since
Feb 18, 2026