First published: Fri Feb 23 2007(Updated: )
Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log file and possibly leverage this for other attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Security and Acceleration Server | =2004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7027 is classified as a medium-severity vulnerability.
To mitigate CVE-2006-7027, apply the latest security updates for Microsoft ISA Server 2004.
CVE-2006-7027 could allow attackers to manipulate log files which may facilitate further attacks.
CVE-2006-7027 affects Microsoft ISA Server 2004.
Yes, by manipulating log files, CVE-2006-7027 may enable attackers to conduct additional attacks.