IIS XSS via IDC error High Medium Low Network Vulnerabilities Web application abuses IIS XSS via IDC error SummaryThis IIS Server appears to be vulnerable to a Cross Site Scripting due to an error in the handling of overlong requests on an idc file. It is possible to inject Javascript in the URL, that will appear in the resulting page. References http://online.securityfocus.com/bid/5900 http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0210&L=ntbugtraq&F=P&S=&P=1391 Updated on 2015-03-25 Severity Classification CVSS Base Score: 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N Related Vulnerabilities AN Guestbook Local File Inclusion VulnerabilityApache Tomcat Directory Listing and File disclosureAdobe ColdFusion HTTP Response Splitting VulnerabilityApache Tomcat TroubleShooter Servlet InstalledAdobe BlazeDS XML and XML External Entity Injection Vulnerabilities