PT-1999-1702 · Microsoft · Iis 4.0+1
Published
1999-03-23
·
Updated
2016-10-18
·
CVE-1999-1397
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Index Server 2.0 on IIS 4.0
Description:
The issue allows local and remote users to obtain the physical paths of directories that are being indexed, as the ContentIndexCatalogs subkey of the AllowedPaths registry key stores this information with permissions that are not restrictive enough.
Recommendations:
For Index Server 2.0 on IIS 4.0, consider restricting access to the AllowedPaths registry key to prevent unauthorized users from obtaining physical path information. As a temporary workaround, restrict access to the ContentIndexCatalogs subkey to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iis 4.0
Index Server 2.0