IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Internet_information_server | Microsoft | 4.0 (including) | 4.0 (including) |
References