Microsoft Forefront Unified Access Gateway 2010 External DNS Interaction
Posted by deepcore on July 3, 2018 – 9:09 pm
Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.
Post a reply
You must be logged in to post a comment.