Vulnerabilities > CVE-2006-7027 - Remote Security vulnerability in Microsoft ISA Server 2004
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log file and possibly leverage this for other attacks.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://www.securityfocus.com/archive/1/432947/30/5190/threaded
- http://www.securityfocus.com/archive/1/433074/30/5190/threaded
- http://www.securityfocus.com/archive/1/433141/30/5160/threaded
- http://www.securityfocus.com/archive/1/433350/30/5100/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26233