3-13834.txt
来自「This is the snapshot of Snot Latest Rule」· 文本 代码 · 共 58 行
TXT
58 行
Rule--Sid3-13834--Summary:This event is generated when an attempt is made to exploit a known vulnerability in Internet Explorer.--Impact:Denial of Service. Information disclosure. Loss of integrity. Complete admin access.--Detailed Information:The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, and (3) bypass referrer restrictions via an incorrect Referer header.--Affected Systems:Microsoft Internet Explorer 7--Attack Scenarios:--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Upgrade to the latest non-affected version of the software.Apply the appropriate vendor supplied patches.--Contributors:Sourcefire Vulnerability Research TeamThis document was generated from data supplied by the National Vulnerability Database. A product of the National Institute of Standards and Technology.For more information see http://nvd.nist.gov/--Additional References:NIST CVE-2008-1544:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1544--
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?