5
CVE-2011-5279
- EPSS 19.24%
- Veröffentlicht 23.04.2014 20:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Information Services Version 4.0
Microsoft ≫ Internet Information Services Version 5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 19.24% | 0.971 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://hi.baidu.com/yuange1975/item/b2cc7141c22108e91e19bc2e
http://seclists.org/fulldisclosure/2012/Apr/0
http://seclists.org/fulldisclosure/2012/Apr/13
http://seclists.org/fulldisclosure/2014/Apr/108
http://seclists.org/fulldisclosure/2014/Apr/128
http://seclists.org/fulldisclosure/2014/Apr/247