Description
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
Affected products
- microsoft / internet_information_server4.0 – 4.0
- microsoft / site_server3.0 – 3.0
- microsoft / site_server_commerce3.0 – 3.0
Updated 10m ago · 8 sources