EIP-2026-118792
PRE-CVEMicrosoft IIS 5.0 - User Existence Disclosure (1)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118792. PoCs published by JeiAr.
AI-analyzed exploit summary This Perl script exploits an information leak vulnerability in Microsoft IIS by brute-forcing user accounts via dictionary attack. It sends HTTP POST requests to the '_AuthChangeUrl' endpoint and checks the response for a pattern indicating a successful password change, thereby confirming the existence of a user account.
Description
Microsoft IIS 5.0 - User Existence Disclosure (1)
Exploits (1)
This Perl script exploits an information leak vulnerability in Microsoft IIS by brute-forcing user accounts via dictionary attack. It sends HTTP POST requests to the '_AuthChangeUrl' endpoint and checks the response for a pattern indicating a successful password change, thereby confirming the existence of a user account.