← All CVEs

CVE-2007-5355

medium · 5.8

The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary DNS suffix with three or more components is configured, resolves an unqualified wpad hostname in a second-level domain outside this configured DNS domain, which allows remote WPAD servers to conduct man-in-the-middle (MITM) attacks.

5.8
CVSS
17.1%
EPSS (exploit prob.)
97th
EPSS percentile
2007-12-05
Published

AV:N/AC:M/Au:N/C:P/I:P/A:N

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftinternet_explorer5.01
microsoftwindows_2000all versions
microsoftinternet_explorer6
microsoftwindows_2003_server64-bit
microsoftwindows_2003_server64-bit_sp2
microsoftwindows_2003_serveritanium_sp1
microsoftwindows_2003_serveritanium_sp2
microsoftwindows_2003_serversp1
microsoftwindows_2003_serversp2
microsoftwindows_xpall versions
microsoftinternet_explorer6
microsoftwindows_2003_server64-bit
microsoftwindows_2003_server64-bit_sp2
microsoftwindows_2003_serveritanium_sp1
microsoftwindows_2003_serveritanium_sp2
microsoftwindows_2003_serversp1
microsoftwindows_2003_serversp2
microsoftwindows_vistaall versions
microsoftwindows_xpall versions
microsoftinternet_explorer7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-5355