CVE-2007-2815
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.
- Affected products
- Internet Information Services (Iis) Web Server, Windows Nt
- Microsoft Internet Information Services
- = 5.0
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 73.4% (99th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2007-05-22
CVE-2007-2815 at NVD
6 known exploits for CVE-2007-2815
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft IIS <= 5.1 Hit Highlighting Authentication Bypass Exploit
CVE-2007-2815.txt
Microsoft IIS <= 5.1 Hit Highlighting Authentication Bypass Exploit
Microsoft IIS <= 5.1 Hit Highlighting Authentication Bypass Exploit
Microsoft IIS 5.1 - Hit Highlighting Authentication Bypass
Microsoft IIS 5.1 - Hit Highlighting Authentication Bypass