CVE-2003-1567 - CVE House
Back to Database
Status published Unknown CVE-2003-1567

The undocumented TRACK method in Microsoft Internet Information Services (IIS)...

Vulnerability Description

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2003-1567

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

internet information services
Vulnerable Versions:
5.0

Timeline

Official Publish: January 15th, 2009
Last Modified: May 28th, 2026
Added to House: July 18th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.