PT-2001-2137 · Microsoft · Index Server
Publicado
2001-09-14
·
Atualizado
2017-12-19
·
CVE-2001-0986
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Index Server 2.0
Description
The issue allows remote attackers to obtain sensitive information, including the physical path, file attributes, or portions of source code, by directly calling the SQLQHit.asp sample file with a specific
CiScope parameter set to values such as webinfo, extended fileinfo, extended webinfo, or fileinfo.Recommendations
For Microsoft Index Server 2.0, consider restricting access to the SQLQHit.asp sample file to prevent direct calls with sensitive
CiScope parameters until a fix is available. As a temporary workaround, avoid using the CiScope parameter with values that could expose sensitive information.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Index Server