// For flags

CVE-2011-5279

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

5
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a
(newline) character in an HTTP header.

Vulnerabilidad de inyección CRLF en la implementación CGI en Microsoft Internet Information Services (IIS) 4.x y 5.x en Windows NT y Windows 2000 permite a atacantes remotos modificar variables de entorno en mayúsculas a través de una caracter
(newline) en una cabecera HTTP.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-04-23 CVE Reserved
  • 2014-04-23 CVE Published
  • 2024-06-09 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
4.0
Search vendor "Microsoft" for product "Internet Information Services" and version "4.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows 2000
Search vendor "Microsoft" for product "Windows 2000"
--
Safe
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
4.0
Search vendor "Microsoft" for product "Internet Information Services" and version "4.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows Nt
Search vendor "Microsoft" for product "Windows Nt"
--
Safe
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
5.0
Search vendor "Microsoft" for product "Internet Information Services" and version "5.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows 2000
Search vendor "Microsoft" for product "Windows 2000"
--
Safe
Microsoft
Search vendor "Microsoft"
Internet Information Services
Search vendor "Microsoft" for product "Internet Information Services"
5.0
Search vendor "Microsoft" for product "Internet Information Services" and version "5.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows Nt
Search vendor "Microsoft" for product "Windows Nt"
--
Safe