Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g594-8xgx-ww3j

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

EPSS

Процентиль: 95%
0.10325
Средний

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 16 лет назад

Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

EPSS

Процентиль: 95%
0.10325
Средний

Дефекты

CWE-79