Описание
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as "Connection" or (2) invalid parameters whose values are echoed in the resulting error message.
Ссылки
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:microsoft:w3who.dll:*:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.13944
Средний
6.8 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as "Connection" or (2) invalid parameters whose values are echoed in the resulting error message.
EPSS
Процентиль: 94%
0.13944
Средний
6.8 Medium
CVSS2
Дефекты
NVD-CWE-Other