Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:10356
Category:CGI abuses
Title:Microsoft's Index server reveals ASP source code
Summary:NOSUMMARY
Description:Description:

It is possible to get the source code of
ASP scripts by issuing the following request :

GET /null.htw?CiWebHitsFile=/default.asp%20&CiRestriction=none&CiHiliteType=Full

ASP source codes usually contain sensitive information such
as usernames and passwords.

Solution : If you need the functionality provided by
WebHits, then install the patch available at :
http://www.microsoft.com/technet/security/bulletin/ms00-006.mspx

If you do not need this functionality, then unmap the
.htw extensions from webhits.dll using the Internet
Service Manager MMC snap-in.

Risk factor : High

Cross-Ref: BugTraq ID: 1084
BugTraq ID: 950
Common Vulnerability Exposure (CVE) ID: CVE-2000-0302
http://www.securityfocus.com/bid/1084
Bugtraq: 20000331 Alert: MS Index Server (CISADV000330) (Google Search)
http://marc.info/?l=bugtraq&m=95453598317340&w=2
Microsoft Security Bulletin: MS00-006
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-006
http://www.osvdb.org/271
XForce ISS Database: http-indexserver-asp-source
Common Vulnerability Exposure (CVE) ID: CVE-2000-0097
http://www.securityfocus.com/bid/950
http://www.osvdb.org/1210
XForce ISS Database: http-indexserver-dirtrans
CopyrightThis script is Copyright (C) 2000 Renaud Deraison

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.