Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
eEye SecureIIS
Vulnerability Description
eEye SecureIIS版本1.0.3及之前版本不对个别HTTP标题执行长度检查,远程攻击者可以向IIS发送任意长度字符串,该漏洞与SecureIIS versions 1.0.3版本及之前版本的广告的功能相反。
CVSS Information
N/A
Vulnerability Type
N/A