ms99-054...

- AV AC AU C I A
发布: 1999-12-02
修订: 2025-04-13

The IE 5 Web Proxy Auto-Discovery (WPAD) feature enables web clients to automatically detect proxy settings without user intervention. The algorithm used by WPAD prepends the hostname "wpad" to the fully-qualified domain name and progressively removes subdomains until it either finds a WPAD server answering the hostname or reaches the third-level domain. A vulnerability arises because in international usage, the third-level domain may not be trusted. A malicious user could set up a WPAD server and serve proxy configuration commands of his or her choice. Microsoft FAQ here.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息