CVE-2009-1535
CVSS Score Not Available
91.83%
HIGH RiskEPSS (100th percentile)
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.
Published: 6/10/2009
Modified: 4/9/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
91.83%HIGH Exploitation Risk
100th percentile
This vulnerability has a 91.83% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.