Microsoft URLScan / RSA Security...

- AV AC AU C I A
发布: 2003-08-14
修订: 2025-04-13

A weakness has been discovered in Microsoft URLScan and RSA Security SecurID when used in conjunction on a web server. The problem is said to occur due to the order in which the products are placed within the global ISAPI filter list. When the vulnerable configuration is in place, an attacker may be capable of enumerating the Microsoft URLScan extension filtering list by making repeated requests to files with differing extensions. The enumeration of this type of information could potentially aid an attacker when launching further attacks against the target web server.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息