NT IIS IDC Path Mapping Vulnerability
BID:299
Info
NT IIS IDC Path Mapping Vulnerability
| Bugtraq ID: | 299 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Jun 04 1999 12:00AM |
| Updated: | Jun 04 1999 12:00AM |
| Credit: | This vulnerability was posted to NTBugtraq by Scott Danahy <[email protected]>. |
| Vulnerable: |
Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: |
Microsoft Windows NT 4.0 SP4 |
Discussion
NT IIS IDC Path Mapping Vulnerability
The full physical path name for the IIS web server root directory may be obtained by attempting to view a non-existent .IDC file. The web server will return an error message that lists the absolute pathname of the "missing" .IDC file.
The full physical path name for the IIS web server root directory may be obtained by attempting to view a non-existent .IDC file. The web server will return an error message that lists the absolute pathname of the "missing" .IDC file.