First published: Tue Aug 23 2005(Updated: )
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =6.0 | |
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2678 is considered a medium severity vulnerability due to its potential for exploitation and impact on security checks.
To fix CVE-2005-2678, apply the latest security patches provided by Microsoft for IIS 5.0 and 6.0.
Attackers can use CVE-2005-2678 to spoof the SERVER_NAME variable, potentially allowing for unauthorized access and bypassing security checks.
CVE-2005-2678 affects Microsoft IIS version 5.0 and 6.0.
While CVE-2005-2678 has been known for many years, it may still pose a risk for organizations using outdated versions of IIS.