Microsoft IIS File Fragment Disclosure Vulnerability
BID:2313
Info
Microsoft IIS File Fragment Disclosure Vulnerability
| Bugtraq ID: | 2313 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2001 12:00AM |
| Updated: | Jan 29 2001 12:00AM |
| Credit: | Posted in a Microsoft Security Bulletin (MS01-004) on Jan 29, 2001. |
| Vulnerable: |
Microsoft IIS 5.0 Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS File Fragment Disclosure Vulnerability
It is possible for a remote attacker to view segments of a requested file. A maliciously crafted URL could cause IIS to use .htr ISAPI extensions to process requests of other file types.
It is possible for a remote attacker to view segments of a requested file. A maliciously crafted URL could cause IIS to use .htr ISAPI extensions to process requests of other file types.
Exploit / POC
Microsoft IIS File Fragment Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IIS File Fragment Disclosure Vulnerability
References:
References: