Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rcm8-cg2r-pcq3

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.

uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.

EPSS

Процентиль: 93%
0.11402
Средний

9.8 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.

EPSS

Процентиль: 93%
0.11402
Средний

9.8 Critical

CVSS3

Дефекты

CWE-918