Microsoft Forefront Unified Access Gateway 2010 External DNS Interaction
Posted on 03 July 2018
Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.