CVE-2007-2815
Status: ModifiedHigh (10)—💥 Exploit
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 73%
- Percentile among all scored CVEs: 99
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Microsoft IIS 5.1 - Hit Highlighting Authentication Bypass (5/31/2007)
Affected technologies (1)
CWEs
- CWE-264
References
- http://osvdb.org/41091
- http://securityreason.com/securityalert/2725
- http://support.microsoft.com/kb/328832
- http://www.securityfocus.com/archive/1/469238/100/0/threaded
- http://www.securityfocus.com/bid/24105
- http://osvdb.org/41091
- http://securityreason.com/securityalert/2725
- http://support.microsoft.com/kb/328832
- http://www.securityfocus.com/archive/1/469238/100/0/threaded
- http://www.securityfocus.com/bid/24105
Raw JSON (NVD)
Show
{
"id": "CVE-2007-2815",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-05-22T19:30:00.000",
"references": [
{
"url": "http://osvdb.org/41091",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/2725",
"source": "cve@mitre.org"
},
{
"url": "http://support.microsoft.com/kb/328832",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/469238/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24105",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/41091",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/2725",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.microsoft.com/kb/328832",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/469238/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/24105",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The \"hit-highlighting\" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw."
},
{
"lang": "es",
"value": "La funcionalidad \"hit-highlighting\" en la biblioteca webhits.dll en el Servidor web versión 5.0 de Internet Information Services (IIS) de Microsoft solo usa la configuración ACL de Windows NT, lo que permite a los atacantes remotos omitir los mecanismos de autenticación básicos y NTLM y acceder a los directorios web privados por medio del parámetro CiWebhitsfile en null.htw."
}
],
"lastModified": "2026-06-16T22:40:29.520",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "413C07EA-139F-4B7D-A58B-835BD2591FA0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}