IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Internet_information_server |
Microsoft |
4.0 (including) |
4.0 (including) |
References