Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.10956
Category:Web Servers
Title:Microsoft IIS 'Codebrws.asp' Source Disclosure Vulnerability - Active Check
Summary:Microsoft's IIS 5.0 web server is shipped with a set of; sample files to demonstrate different features of the ASP language. One of these sample; files allows a remote user to view the source of any file in the web root with the extension; .asp, .inc, .htm, or .html.
Description:Summary:
Microsoft's IIS 5.0 web server is shipped with a set of
sample files to demonstrate different features of the ASP language. One of these sample
files allows a remote user to view the source of any file in the web root with the extension
.asp, .inc, .htm, or .html.

Solution:
Remove the /IISSamples virtual directory using the Internet Services Manager.

If for some reason this is not possible, removing the following ASP script will fix the problem:

This path assumes that you installed IIS in c:\inetpub

c:\inetpub\iissamples\sdk\asp\docs\CodeBrws.asp

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-1999-0739
Microsoft Security Bulletin: MS99-013
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013
Microsoft Knowledge Base article: Q231368
Microsoft Knowledge Base article: Q232449
CopyrightCopyright (C) 2002 Matt Moore / HD Moore

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.