Microsoft FrontPage PWS Directory Traversal Vulnerability
BID:989
Info
Microsoft FrontPage PWS Directory Traversal Vulnerability
| Bugtraq ID: | 989 |
| Class: | Input Validation Error |
| CVE: |
CVE-2000-0153 CVE-1999-0386 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 17 1996 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | Originally posted to Bugtraq on January 17, 1996 by kiborg <[email protected]>. |
| Vulnerable: |
Microsoft Personal Web Server 4.0 Microsoft FrontPage Personal WebServer 1.0 |
| Not Vulnerable: |
Microsoft Personal Web Server 2.0 Microsoft Personal Web Server 1.0 |
Discussion
Microsoft FrontPage PWS Directory Traversal Vulnerability
Microsoft's Personal Web Server and Front Page Personal Web Server will follow '/..../' strings in requested URLs, allowing remote users to obtain unauthenticated read access to files and directories on the same logical drive as the web content. Hidden files are viewable via this method, although the Front Page directory itself is not. The name and path of the desired file must be known to the attacker.
Note that while these programs support Windows 95, 98 and NT, only the Win9x versions are vulnerable.
Microsoft's Personal Web Server and Front Page Personal Web Server will follow '/..../' strings in requested URLs, allowing remote users to obtain unauthenticated read access to files and directories on the same logical drive as the web content. Hidden files are viewable via this method, although the Front Page directory itself is not. The name and path of the desired file must be known to the attacker.
Note that while these programs support Windows 95, 98 and NT, only the Win9x versions are vulnerable.
Exploit / POC
Microsoft FrontPage PWS Directory Traversal Vulnerability
http://target/..../directory/filename.ext
http://target/..../directory/filename.ext
Solution / Fix
Microsoft FrontPage PWS Directory Traversal Vulnerability
Solution:
Microsoft has provided patches for this issue, available at:
Personal Web Server:
http://support.microsoft.com/download/support/mslfiles/Pwssecup.exe
Front Page 98:
http://officeupdate.microsoft.com/downloadDetails/fppws98.htm
Front Page 97:
Upgrade tp PWS4.0, available at:
/http://www.microsoft.com/windows/ie/pws/default.htm
Then apply the patch at
http://support.microsoft.com/download/support/mslfiles/Pwssecup.exe
If remote authoring support is required, you will need to apply new extensions, modify an .ini file, and apply a different patch. Full directions are available in Knowledge Base article Q217765, available at:
http://support.microsoft.com/support/kb/articles/Q217/7/65.ASP
For more details on which patch to apply, see the advisory (linked to in the credit section)
Solution:
Microsoft has provided patches for this issue, available at:
Personal Web Server:
http://support.microsoft.com/download/support/mslfiles/Pwssecup.exe
Front Page 98:
http://officeupdate.microsoft.com/downloadDetails/fppws98.htm
Front Page 97:
Upgrade tp PWS4.0, available at:
/http://www.microsoft.com/windows/ie/pws/default.htm
Then apply the patch at
http://support.microsoft.com/download/support/mslfiles/Pwssecup.exe
If remote authoring support is required, you will need to apply new extensions, modify an .ini file, and apply a different patch. Full directions are available in Knowledge Base article Q217765, available at:
http://support.microsoft.com/support/kb/articles/Q217/7/65.ASP
For more details on which patch to apply, see the advisory (linked to in the credit section)
References
Microsoft FrontPage PWS Directory Traversal Vulnerability
References:
References: