Microsoft URLScan Tool Information...

- AV AC AU C I A
发布: 2003-07-03
修订: 2025-04-13

Microsoft URLScan has been reported prone to an information disclosure vulnerability in some server configurations. It has been reported that a remote attacker may disclose accurate IIS server HTTP header information, regardless of whether the server is protected by the URLScan tool. The issue presents itself when an attacker makes a HTTPS request to an IIS server that is HTTPS enabled. A partial header will be returned to the attacker containing potentially sensitive version information.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息