Exploit Microsoft IIS 4.0/5.0/6.0 - Internal IP Address/Internal Network Name Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21057
Проверка EDB
  1. Пройдено
Автор
MAREK ROY
Тип уязвимости
REMOTE
Платформа
WINDOWS
CVE
null
Дата публикации
2001-08-08
Код:
source: https://www.securityfocus.com/bid/3159/info

A vulnerability has been discovered in Microsoft IIS that may disclose the internal IP address or internal network name to remote attackers. This vulnerability can be exploited if an attacker connects to a host using HTTPS (typically on port 443) and crafts a specially formed GET request. Microsoft IIS will return a 302 Object Moved error message containing the internal IP address or internal network name of the server.

It has been reported that a target host using HTTP is also vulnerable to this issue. 

GET /directory HTTP/1.0
 
Источник
www.exploit-db.com

Похожие темы