Description
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
Remediation
References
Related Vulnerabilities
MySQL CVE-2012-1702 Vulnerability (CVE-2012-1702)
Oracle JRE Improper Access Control Vulnerability (CVE-2026-62574)
WordPress Cross-Domain Flash Injection Vulnerability (0.70 - 3.6.1)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-8286)
Rukovoditel Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-20166)