![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.10577 |
Category: | Web Servers |
Title: | Microsoft IIS 'bdir.htr' Default Files - Active Check |
Summary: | The file bdir.htr is a default IIS files which can give; a malicious user a lot of unnecessary information about your file system. |
Description: | Summary: The file bdir.htr is a default IIS files which can give a malicious user a lot of unnecessary information about your file system. Vulnerability Impact: Specifically, the bdir.htr script allows the user to browse and create files on hard drive. As this includes critical system files, it is highly possible that the attacker will be able to use this script to escalate privileges and gain 'Administrator' access. Example: http://example.com/scripts/iisadmin/bdir.htr??c: Solution: If you do not need these files, then delete them, otherwise use suitable access control lists to ensure that the files are not world-readable. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N |
Copyright | Copyright (C) 2003 John Lampe |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |