IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/3892 | vdb entry |
http://support.microsoft.com/support/kb/articles/q187/5/03.asp | patch vendor advisory |