Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g594-8xgx-ww3j

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

EPSS

Процентиль: 89%
0.04959
Низкий

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 15 лет назад

Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

EPSS

Процентиль: 89%
0.04959
Низкий

Дефекты

CWE-79