NT IIS4 Shared ASP Cache Vulnerability
BID:195
Info
NT IIS4 Shared ASP Cache Vulnerability
| Bugtraq ID: | 195 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Jan 27 1999 12:00AM |
| Updated: | Jan 27 1999 12:00AM |
| Credit: | This vulnerability was posted to NTBugtraq mailing list by Ivan Hamilton <[email protected]> |
| Vulnerable: |
Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
NT IIS4 Shared ASP Cache Vulnerability
Two separate web servers may be configured to share the same physical directory on an IIS directory. There may be instances where ASP information containing confidential information (from site A) is presented in ASP information served to a user from site B.
Two separate web servers may be configured to share the same physical directory on an IIS directory. There may be instances where ASP information containing confidential information (from site A) is presented in ASP information served to a user from site B.
Exploit / POC
NT IIS4 Shared ASP Cache Vulnerability
see discussion
see discussion
Solution / Fix
NT IIS4 Shared ASP Cache Vulnerability
Solution:
Microsoft has released a patch for this problem:
http://support.microsoft.com/support/kb/articles/q197/0/03.asp?FR=0
Solution:
Microsoft has released a patch for this problem:
http://support.microsoft.com/support/kb/articles/q197/0/03.asp?FR=0
References
NT IIS4 Shared ASP Cache Vulnerability
References:
References: