Описание
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:microsoft:internet_information_server:3.0:*:*:ja:*:*:*:*
cpe:2.3:a:microsoft:internet_information_server:3.0:*:*:ko:*:*:*:*
cpe:2.3:a:microsoft:internet_information_server:3.0:*:*:zh:*:*:*:*
cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:ja:*:*:*:*
cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:ko:*:*:*:*
cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:zh:*:*:*:*
EPSS
Процентиль: 97%
0.38532
Средний
7.1 High
CVSS2
Дефекты
CWE-16
Связанные уязвимости
github
около 3 лет назад
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
EPSS
Процентиль: 97%
0.38532
Средний
7.1 High
CVSS2
Дефекты
CWE-16