EIP-2026-118797
PRE-CVEMicrosoft IIS 6.0/7.5 (+ PHP) - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118797. PoCs published by kingcope.
AI-analyzed exploit summary This writeup describes multiple authentication bypass vulnerabilities in Microsoft IIS 6.0 and 7.5, leveraging special path suffixes like '::$INDEX_ALLOCATION' to bypass access restrictions on protected directories. It also details a source code disclosure vulnerability in IIS 7.5 with specific PHP configurations.
Description
Microsoft IIS 6.0/7.5 (+ PHP) - Multiple Vulnerabilities
Exploits (1)
This writeup describes multiple authentication bypass vulnerabilities in Microsoft IIS 6.0 and 7.5, leveraging special path suffixes like '::$INDEX_ALLOCATION' to bypass access restrictions on protected directories. It also details a source code disclosure vulnerability in IIS 7.5 with specific PHP configurations.