Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:10356
Category:CGI abuses
Title:Microsoft's Index server reveals ASP source code

It is possible to get the source code of
ASP scripts by issuing the following request :

GET /null.htw?CiWebHitsFile=/default.asp%20&CiRestriction=none&CiHiliteType=Full

ASP source codes usually contain sensitive information such
as usernames and passwords.

Solution : If you need the functionality provided by
WebHits, then install the patch available at :

If you do not need this functionality, then unmap the
.htw extensions from webhits.dll using the Internet
Service Manager MMC snap-in.

Risk factor : High

Cross-Ref: BugTraq ID: 1084
BugTraq ID: 950
Common Vulnerability Exposure (CVE) ID: CVE-2000-0302
Bugtraq: 20000331 Alert: MS Index Server (CISADV000330) (Google Search)
Microsoft Security Bulletin: MS00-006
XForce ISS Database: http-indexserver-asp-source
Common Vulnerability Exposure (CVE) ID: CVE-2000-0097
XForce ISS Database: http-indexserver-dirtrans
CopyrightThis script is Copyright (C) 2000 Renaud Deraison

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2024 E-Soft Inc. All rights reserved.