Microsoft URLScan Information Disclosure Weakness
BID:7767
Info
Microsoft URLScan Information Disclosure Weakness
| Bugtraq ID: | 7767 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2003 12:00AM |
| Updated: | May 31 2003 12:00AM |
| Credit: | Discovery of this issue credited to Stephen Cope <[email protected]>. |
| Vulnerable: |
Microsoft URLScan 2.5 Microsoft URLScan 2.0 |
| Not Vulnerable: | |
Discussion
Microsoft URLScan Information Disclosure Weakness
A weakness has been reported for URLScan that may result in the disclosure of sensitive information.
The weakness exists because of the way URLScan handles HEAD HTTP requests. Specifically, when URLScan receives a HEAD request that is subsequently rejected, it is automatically converted to a GET request and sent to the underlying IIS server.
The information returned may allow an attacker to identify systems that incorporate the use of URLScan.
A weakness has been reported for URLScan that may result in the disclosure of sensitive information.
The weakness exists because of the way URLScan handles HEAD HTTP requests. Specifically, when URLScan receives a HEAD request that is subsequently rejected, it is automatically converted to a GET request and sent to the underlying IIS server.
The information returned may allow an attacker to identify systems that incorporate the use of URLScan.