Описание
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2000-0024
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-061
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ246401
- http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246401
- http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt
EPSS
Процентиль: 94%
0.12045
Средний
CVE ID
Связанные уязвимости
nvd
около 26 лет назад
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
EPSS
Процентиль: 94%
0.12045
Средний