This vuln is not exploitable in this condition against IIS server 6
and possibly earlier versions. IIS will die on the null character in
the new request. It doesn't seem like anyone has brought up this
fact.
Example (IIS): location.hostname='microsoft.com\x00www.coredump.cx';
and possibly earlier versions. IIS will die on the null character in
the new request. It doesn't seem like anyone has brought up this
fact.
Example (IIS): location.hostname='microsoft.com\x00www.coredump.cx';
Output:
microsoft.c...
[ more ]