CVE

Id
3338  
CVE No.
CVE-2001-0524  
Status
Candidate  
Description
eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.  
Phase
Proposed (20010727)  
Votes
ACCEPT(4) Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall  
Comments