AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2003-1306

LOW · CVSS 2.6 EPSS 1.25%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2003-12-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2003-1306
Severity
LOW
CVSS
2.6
EPSS
1.25%
Microsoft

Original NVD Description

Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.