EIP-2026-118793

PRE-CVE

Microsoft IIS 5.0 - User Existence Disclosure (2)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118793. PoCs published by JeiAr.

AI-analyzed exploit summary This script is a user enumeration tool for Microsoft IIS, exploiting an information leak vulnerability where different error messages are returned based on whether a user exists. It performs a dictionary attack against the IIS Authentication Manager to identify valid user accounts.

Description

Microsoft IIS 5.0 - User Existence Disclosure (2)

Exploits (1)

exploitdb SCANNER VERIFIED
by JeiAr · perlremotewindows
https://www.exploit-db.com/exploits/22563

This script is a user enumeration tool for Microsoft IIS, exploiting an information leak vulnerability where different error messages are returned based on whether a user exists. It performs a dictionary attack against the IIS Authentication Manager to identify valid user accounts.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Microsoft IIS
No auth needed
Prerequisites: Network access to the target IIS server · A list of potential usernames (wordlist)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026