PT-2001-2137 · Microsoft · Index Server

Publicado

2001-09-14

·

Atualizado

2017-12-19

·

CVE-2001-0986

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Index Server 2.0
Description The issue allows remote attackers to obtain sensitive information, including the physical path, file attributes, or portions of source code, by directly calling the SQLQHit.asp sample file with a specific CiScope parameter set to values such as webinfo, extended fileinfo, extended webinfo, or fileinfo.
Recommendations For Microsoft Index Server 2.0, consider restricting access to the SQLQHit.asp sample file to prevent direct calls with sensitive CiScope parameters until a fix is available. As a temporary workaround, avoid using the CiScope parameter with values that could expose sensitive information.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0986

Produtos afetados

Index Server