| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.10492 |
| Category: | Web Servers |
| Title: | IIS IDA/IDQ Path Disclosure |
| Summary: | Determines IIS IDA/IDQ Path Reveal vulnerability |
| Description: | IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. An attacker may use this flaw to gain more information about the remote host, and hence make more focused attacks. Solution: Select 'Preferences ->Home directory ->Application', and check the checkbox 'Check if file exists' for the ISAPI mappings of your server. |
| Cross-Ref: |
BugTraq ID: 1065 Common Vulnerability Exposure (CVE) ID: CVE-2000-0071 Bugtraq: 20000111 IIS still revealing paths for web directories (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=94770020309953&w=2 Bugtraq: 20000113 SV: IIS still revealing paths for web directories (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=94780058006791&w=2 |
| Copyright | This script is Copyright (C) 2000 Filipe Custodio |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|