CVE-2007-2815

Microsoft IIS Web Server 5.0 - Auth Bypass

Title source: llm

Description

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Sha0 · bashremotewindows
https://www.exploit-db.com/exploits/4016

Scores

EPSS 0.8587
EPSS Percentile 99.4%

Details

CWE
CWE-264
Status published
Products (1)
microsoft/internet_information_services 5.0
Published May 22, 2007
Tracked Since Feb 18, 2026