← back
CVE-2009-1122

CVE-2009-1122

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 98%
from disclosure to weapon0 days
Published on NVDJun 10
1st PoCMay 26
exploitation probability
98%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.