First published: Tue Jun 14 2005(Updated: )
Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Security and Acceleration Server | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1215 is considered a critical vulnerability due to its potential to allow cache poisoning and policy bypass.
CVE-2005-1215 allows remote attackers to exploit multiple Content-Length headers in HTTP requests to compromise caching mechanisms.
The risks include unauthorized access to restricted content and the possibility of serving incorrect data from the ISA cache.
To mitigate CVE-2005-1215, upgrade Microsoft ISA Server to a version that addresses this vulnerability.
Implementing strict input validation and monitoring for unusual HTTP requests can help temporarily mitigate the risks of CVE-2005-1215.