PT-2001-2137 · Microsoft · Index Server
Published
2001-09-14
·
Updated
2017-12-19
·
CVE-2001-0986
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Index Server 2.0
Description
The issue allows remote attackers to obtain sensitive information, including the physical path, file attributes, or portions of source code, by directly calling the SQLQHit.asp sample file with a specific
CiScope parameter set to values such as webinfo, extended fileinfo, extended webinfo, or fileinfo.Recommendations
For Microsoft Index Server 2.0, consider restricting access to the SQLQHit.asp sample file to prevent direct calls with sensitive
CiScope parameters until a fix is available. As a temporary workaround, avoid using the CiScope parameter with values that could expose sensitive information.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Index Server