Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NT IIS SSL DoS漏洞
Vulnerability Description
IIS 3.x及4.x版本存在漏洞。IIS 3.x及4.x版本不能区分需要加密术的页面和不需要的页面,远程攻击者借助一般不加密文件HPPTS端口的SSL请求导致服务拒绝(资源耗尽),该漏洞导致IIS执行额外工作来发送SSL之上的文件。
CVSS Information
N/A
Vulnerability Type
N/A