MEDIUM
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request
Published Jun 11, 2002
5.0
MEDIUMCVSS 2.0
EPSS 37.30%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.