CVE-2009-1122 is a critical authentication bypass vulnerability affecting Microsoft IIS 5.0 on Windows 2000 SP4, specifically within its WebDAV extension. This flaw allows remote, unauthenticated attackers to bypass security mechanisms by sending specially crafted HTTP requests due to improper URL decoding. With a CVSS score of 7.5 and an EPSS percentile of 90.56%, this vulnerability poses a significant risk, potentially enabling unauthorized file reading or creation. Exploit code, including Metasploit modules and an ExploitDB entry, is publicly available, although it is not listed in the KEV catalog and has minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.