PT-1999-1702 · Microsoft · Iis 4.0+1

Publicado

1999-03-23

·

Atualizado

2016-10-18

·

CVE-1999-1397

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Index Server 2.0 on IIS 4.0
Description: The issue allows local and remote users to obtain the physical paths of directories that are being indexed, as the ContentIndexCatalogs subkey of the AllowedPaths registry key stores this information with permissions that are not restrictive enough.
Recommendations: For Index Server 2.0 on IIS 4.0, consider restricting access to the AllowedPaths registry key to prevent unauthorized users from obtaining physical path information. As a temporary workaround, restrict access to the ContentIndexCatalogs subkey to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1397

Produtos afetados

Iis 4.0
Index Server 2.0