IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T02:49:28.459Z
Reserved: 2002-06-07T00:00:00
Link: CVE-2002-0422
No data.
Status : Deferred
Published: 2002-08-12T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2002-0422
No data.
OpenCVE Enrichment
No data.
Weaknesses