MS Frontpage htimage.exe Path Leak Vulnerability
BID:964
Info
MS Frontpage htimage.exe Path Leak Vulnerability
| Bugtraq ID: | 964 |
| Class: | Design Error |
| CVE: |
CVE-2000-0122 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 03 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | Posted to Bugtraq on February 3, 2000 by Mnemonix <[email protected]>. |
| Vulnerable: |
Microsoft FrontPage 98 Microsoft FrontPage 2000 |
| Not Vulnerable: | |
Discussion
MS Frontpage htimage.exe Path Leak Vulnerability
A GET request to htimage.exe may return its physical path, revealing the file structure of the website. htimage.exe can be found in the /scripts or /cgi-bin directory.
For example, http://target/cgi-bin/htimage.exe?2.2 may reveal the physical path as being E:\website\cgi.
A GET request to htimage.exe may return its physical path, revealing the file structure of the website. htimage.exe can be found in the /scripts or /cgi-bin directory.
For example, http://target/cgi-bin/htimage.exe?2.2 may reveal the physical path as being E:\website\cgi.
Exploit / POC
MS Frontpage htimage.exe Path Leak Vulnerability
see discussion
see discussion