PT-2002-2630 · Microsoft · Iis
Published
2002-12-31
·
Updated
2020-11-23
·
CVE-2002-1908
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft IIS versions 5.0 through 5.1
Description
The issue allows remote attackers to cause a denial of service, specifically CPU consumption, by sending an HTTP request with a Host header containing a large number of "/" (forward slash) characters.
Recommendations
For Microsoft IIS versions 5.0 through 5.1, consider restricting access to the HTTP request handler to minimize the risk of exploitation. As a temporary workaround, limit the size of the Host header to prevent excessive CPU consumption.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iis