Vulnerability Name: | CVE-2011-5279 (CCN-110865) | ||||||||
Assigned: | 2012-04-01 | ||||||||
Published: | 2012-04-01 | ||||||||
Updated: | 2020-11-23 | ||||||||
Summary: | CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-5279 Source: MISC Type: Third Party Advisory http://hi.baidu.com/yuange1975/item/b2cc7141c22108e91e19bc2e Source: CCN Type: Full-Disclosure Mailing List, Sun, 1 Apr 2012 07:51:09 +0000 FW: iis bug Source: FULLDISC Type: Exploit, Mailing List, Third Party Advisory 20120401 FW: iis bug Source: FULLDISC Type: Exploit, Mailing List, Third Party Advisory 20120402 Re: iis bug Source: FULLDISC Type: Exploit, Mailing List, Third Party Advisory 20140409 iis cgi 0day Source: FULLDISC Type: Exploit, Mailing List, Third Party Advisory 20140410 Re: iis cgi 0day Source: FULLDISC Type: Exploit, Mailing List, Third Party Advisory 20140419 Re: iis cgi 0day Source: CCN Type: Microsoft Web site Internet Information Services Source: XF Type: UNKNOWN ms-iis-cve20115279-sec-bypass(110865) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |