peter bassill · operator
$ cve CVE-2003-1566 JSON

CVE-2003-1566 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 28.1% (pctl 98)

Patch early

A public exploit exists.

Description

Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS28.12% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-16
On CISA KEVno
Public exploityes
Published2009-01-15
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet information services

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD