Lucene search

K
cve[email protected]CVE-2001-0524
HistoryAug 14, 2001 - 4:00 a.m.

CVE-2001-0524

2001-08-1404:00:00
web.nvd.nist.gov
25
cve-2001-0524
secureiis
version 1.0.3
http headers
remote attack
length checks

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

83.2%

eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.

Affected configurations

NVD
Node
eeye_digital_securitysecurellsRange1.0.3

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.009 Low

EPSS

Percentile

83.2%

Related for CVE-2001-0524