CVE Database
/

CVE-2003-1567

Back to search

CVE-2003-1567

Published: Jan 15, 2009

Modified: May 28, 2026

PUBLISHED

Description

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#288308
third-party-advisory
x_refsource_CERT-VN
5648
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2003-1567 - Security Vulnerability | QwikSec