LIVE NEWSROOM · --:-- · May 24, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2005-2089

CVE-2005-2089

CVSS 4.3 · MEDIUM

Summary

Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

CVSS 2.0 breakdown

Base score4.3 (MEDIUM)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Attack vectorNETWORK
Attack complexityMEDIUM
ConfidentialityNONE
IntegrityPARTIAL
AvailabilityNONE

Weakness type (CWE)

Affected products

Microsoft internet information services
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top