CVE-2011-5279
Summary
| CVE | CVE-2011-5279 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-23 20:55:00 UTC |
| Updated | 2020-11-23 19:47:00 UTC |
| Description | CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Information Services | 4.0 | All | All | All |
| Application | Microsoft | Internet Information Services | 5.0 | All | All | All |
| Application | Microsoft | Internet Information Services | 4.0 | All | All | All |
| Application | Microsoft | Internet Information Services | 5.0 | All | All | All |
| Operating System | Microsoft | Windows 2000 | - | All | All | All |
| Operating System | Microsoft | Windows 2000 | - | All | All | All |
| Operating System | Microsoft | Windows Nt | - | All | All | All |
| Operating System | Microsoft | Windows Nt | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: Re: iis bug | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Full Disclosure: iis cgi 0day | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Full Disclosure: FW: iis bug | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Full Disclosure: Re: iis cgi 0day | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Full Disclosure: Re: iis cgi 0day | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| 如流,新一代智能工作平台 | MISC | hi.baidu.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.