Microsoft URLScan Information...

- AV AC AU C I A
发布: 2003-05-31
修订: 2025-04-13

A weakness has been reported for URLScan that may result in the disclosure of sensitive information. The weakness exists because of the way URLScan handles HEAD HTTP requests. Specifically, when URLScan receives a HEAD request that is subsequently rejected, it is automatically converted to a GET request and sent to the underlying IIS server. The information returned may allow an attacker to identify systems that incorporate the use of URLScan.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息