CVE-2003-1567

N/A Unknown
Published: January 15, 2009 Modified: April 23, 2026
View on NVD

Description

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.kb.cert.org/vuls/id/288308
Source: cve@mitre.org
US Government Resource
http://www.osvdb.org/5648
Source: cve@mitre.org
Exploit
http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.aqtronix.com/Advisories/AQ-2003-02.txt
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.kb.cert.org/vuls/id/288308
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.osvdb.org/5648
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
69.0%
99th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

microsoft