vendor:
IIS
by:
David Litchfield
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: IIS
Affected Version From: IIS 4.0
Affected Version To: IIS 4.0
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:iis:4.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
1999
IIS4 Long Request Vulnerability
An http get request against an IIS4 server will not be logged if the request is longer than 10150 bytes long.
Mitigation:
Upgrade to IIS 5.0 or later