PT-2000-1702 · Microsoft · Iis
Published
2000-10-20
·
Updated
2018-10-30
·
CVE-2000-0770
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IIS versions 4.0 through 5.0
Description
The issue arises from improper restriction of access to certain file types when their parent folders have less restrictive permissions. This could allow remote attackers to bypass access restrictions to some files.
Recommendations
For IIS version 4.0, update the permissions to properly restrict access to sensitive files.
For IIS version 5.0, apply the same update to ensure that file access restrictions are properly enforced.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iis