Security Portal

Intrusion Prevention Service

Signature Version: 4.876


WEB Microsoft ISA Server HTTP Content Header Vulnerability (CVE-2005-1215)
Threat Level: High
Release Date: 2010/6/9
Category: Access Control
Signature ID: 1112370
Included In: Full
Affected OS: Windows
Description: Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
Impact: Remote code execution
Recommendation: Update vendor's patch.
False Positive: None
False Negative: None
Additional Information (Links open in new window):
Reference(s): CVE-2005-1215

Search the Threat Database
Enter Rule ID or Name