MS Index Services and Indexing Services Path Disclosure Vulnerability
BID:2710
Info
MS Index Services and Indexing Services Path Disclosure Vulnerability
| Bugtraq ID: | 2710 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2000 12:00AM |
| Updated: | Mar 30 2000 12:00AM |
| Credit: | Discovered by David Litchfield of Cerberus Information Security, and posted in Microsoft Security Bulletin (MS00-006). |
| Vulnerable: |
Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Advanced Server Microsoft Index Server 2.0 |
| Not Vulnerable: |
Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Advanced Server SP1 |
Discussion
MS Index Services and Indexing Services Path Disclosure Vulnerability
Requesting a non-existent resource along with a known directory to a system running Index Server 2.0 and Indexing Services, will disclose an error message containing the physical path to the requested web directory.
Requesting a non-existent resource along with a known directory to a system running Index Server 2.0 and Indexing Services, will disclose an error message containing the physical path to the requested web directory.
Exploit / POC
MS Index Services and Indexing Services Path Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MS Index Services and Indexing Services Path Disclosure Vulnerability
Solution:
Microsoft has released patches to rectify this issue:
Microsoft Windows NT Enterprise Server 4.0
Microsoft Windows NT Enterprise Server 4.0 SP2
Microsoft Index Server 2.0
Microsoft Windows NT Server 4.0 SP3
Microsoft Windows NT Enterprise Server 4.0 SP3
Microsoft Windows NT Server 4.0 SP1
Microsoft Windows NT Enterprise Server 4.0 SP4
Microsoft Windows NT Enterprise Server 4.0 SP6
Microsoft Windows NT Server 4.0
Microsoft Windows NT Enterprise Server 4.0 SP5
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT Server 4.0 SP6
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows NT Server 4.0 SP2
Microsoft Windows NT Server 4.0 SP5
Microsoft Windows NT Enterprise Server 4.0 SP1
Microsoft Windows NT Server 4.0 SP4
Solution:
Microsoft has released patches to rectify this issue:
Microsoft Windows NT Enterprise Server 4.0
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Enterprise Server 4.0 SP2
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Index Server 2.0
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727
Microsoft Windows NT Server 4.0 SP3
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Enterprise Server 4.0 SP3
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Server 4.0 SP1
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Enterprise Server 4.0 SP4
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Enterprise Server 4.0 SP6
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Server 4.0
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Enterprise Server 4.0 SP5
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728 -
Microsoft Q299444
Post-Windows NT 4.0 Service Pack 6a Security Rollup.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q299444
Microsoft Windows NT Server 4.0 SP6
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728 -
Microsoft Q299444
Post-Windows NT 4.0 Service Pack 6a Security Rollup.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q299444
Microsoft Windows NT Server 4.0 SP2
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Server 4.0 SP5
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Enterprise Server 4.0 SP1
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
Microsoft Windows NT Server 4.0 SP4
-
Microsoft Q252463
http://www.microsoft.com/downloads/release.asp?ReleaseID=17727 -
Microsoft Q252463
Windows NT Alpha
http://www.microsoft.com/downloads/release.asp?ReleaseID=17728
References
MS Index Services and Indexing Services Path Disclosure Vulnerability
References:
References: