PT-2000-1228 · Microsoft · Iis
Publicado
2000-03-30
·
Atualizado
2018-10-30
·
CVE-2000-0246
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IIS versions 4.0 through 5.0
Description
The issue arises from improper ISAPI extension processing when a virtual directory is mapped to a UNC share. This allows remote attackers to read the source code of ASP and other files.
Recommendations
For IIS versions 4.0 through 5.0, consider remapping virtual directories to local paths instead of UNC shares to prevent exploitation. Additionally, restrict access to sensitive files and directories to minimize the risk of source code disclosure.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iis