Description
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
Affected products
Exploits & proofs of concept
- exploit-dbMicrosoft IIS 4 (Windows NT) - Log Avoidanceby Mnemonix
Updated 38m ago · 8 sources