Description
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
Remediation
References
Related Vulnerabilities
MongoDb Reliance on Untrusted Inputs in a Security Decision Vulnerability (CVE-2026-13059)
WordPress Plugin Subscriptions & Memberships for PayPal Unspecified Vulnerability (1.1.5)
WordPress Plugin WordPress Backup and Migrate-Backup Guard Arbitrary File Upload (1.0.2)
Liferay Portal Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-4581)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2016-1240)