Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft IIS安全检查绕过漏洞
Vulnerability Description
Microsoft IIS(Internet Information Server)是Microsoft Windows系统默认自带的Web服务器软件,其中默认包含FTP服务。 Microsoft IIS 5.1和6版本中存在漏洞。远程攻击者可借助带有http://localhost URI的GET请求欺骗SERVER_NAME变量以绕过安全检查并进行各种攻击。
CVSS Information
N/A
Vulnerability Type
N/A