PT-2001-2137 · Microsoft · Index Server

Published

2001-09-14

·

Updated

2017-12-19

·

CVE-2001-0986

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Index Server 2.0
Description The issue allows remote attackers to obtain sensitive information, including the physical path, file attributes, or portions of source code, by directly calling the SQLQHit.asp sample file with a specific CiScope parameter set to values such as webinfo, extended fileinfo, extended webinfo, or fileinfo.
Recommendations For Microsoft Index Server 2.0, consider restricting access to the SQLQHit.asp sample file to prevent direct calls with sensitive CiScope parameters until a fix is available. As a temporary workaround, avoid using the CiScope parameter with values that could expose sensitive information.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0986

Affected Products

Index Server