EIP-2026-118794
PRE-CVEMicrosoft IIS 5.1 - WebDAV HTTP Request Source Code Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118794. PoCs published by Inge Henriksen.
AI-analyzed exploit summary This exploit leverages a path traversal vulnerability in Microsoft IIS 5.1 by sending a specially crafted HTTP GET request with a malformed filename (using Unicode encoding) to disclose the source code of scripts stored on FAT/FAT32 volumes. The 'Translate: f' header forces the server to return the file as plain text.
Description
Microsoft IIS 5.1 - WebDAV HTTP Request Source Code Disclosure
Exploits (1)
This exploit leverages a path traversal vulnerability in Microsoft IIS 5.1 by sending a specially crafted HTTP GET request with a malformed filename (using Unicode encoding) to disclose the source code of scripts stored on FAT/FAT32 volumes. The 'Translate: f' header forces the server to return the file as plain text.