Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-0902

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2001-0902
Last Modified 05 Sep 2008 04:25:11
Published 20 Nov 2001 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2001-0902

Summary

Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.

Vulnerable Systems

Application

  • Microsoft Internet Information Server 5.0


References

XF - iis-fake-log-entry(7613)

BID - 6795

BUGTRAQ - 20011120 IIS logging issue


Last Updated: 27 May 2016 10:36:26