CVE-2005-2678

EXPLOITED

Microsoft Internet Information Server 5.1 and 6 - Server Name Spoofing via Localhost URI

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2005-2678 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.

References (4)

Core 4
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1503
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16548
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112474727903399&w=2

Scores

EPSS 0.3981
EPSS Percentile 98.5%

Details

VulnCheck KEV 2018-01-15
Status published
Products (2)
microsoft/internet_information_server 6.0
microsoft/internet_information_services 5.0
Published Aug 23, 2005
Tracked Since Feb 18, 2026