CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects Microsoft. Its EPSS score suggests a 98.1% probability of exploitation in the next 30 days. It may be remotely exploitable.
Original NVD Description
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.