PT-1999-1702 · Microsoft · Iis 4.0+1
Publicado
1999-03-23
·
Atualizado
2016-10-18
·
CVE-1999-1397
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Index Server 2.0 on IIS 4.0
Description:
The issue allows local and remote users to obtain the physical paths of directories that are being indexed, as the ContentIndexCatalogs subkey of the AllowedPaths registry key stores this information with permissions that are not restrictive enough.
Recommendations:
For Index Server 2.0 on IIS 4.0, consider restricting access to the AllowedPaths registry key to prevent unauthorized users from obtaining physical path information. As a temporary workaround, restrict access to the ContentIndexCatalogs subkey to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iis 4.0
Index Server 2.0