Improper input validation in Microsoft Forefront Unified Access Gateway - CVE-2018-12571
Published: July 3, 2018 / Updated: July 6, 2018
Microsoft Forefront Unified Access Gateway
Detailed vulnerability description
The vulnerability allows a remote attacker to modify system information on the target system.
The vulnerability exists due to an error when processing malicious input. A remote attacker can submit a specially crafted 'orig_url' parameter value that includes a comma-separated list of URLs and cause the target server to initiate DNS queries for the hosts specified in the URLs.