Microsoft IIS Escape Character...

- AV AC AU C I A
发布: 1999-12-21
修订: 2025-04-13

IIS accepts escaped characters that are not valid hexadecimal digits. All webservers that are compliant with RFC 1738 accept hexadecimal digits that are preceded by a percent sign, but IIS will also accept invalid hex digits and translate some of them into valid ASCII characters. This provides a third means of constructing URLs (plaintext, valid hex, and invalid hex) that may be used to bypass third-party access control mechanisms and intrusion detection systems. This issue does not provide a means of compromising the IIS server itself.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息