Skip to main content

CVE-2009-1122

CVSS Score Not Available
92.34%
HIGH RiskEPSS (100th percentile)

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.

Published: 6/10/2009
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

92.34%HIGH Exploitation Risk
100th percentile

This vulnerability has a 92.34% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.