|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Microsoft IIS contains a flaw that allows a remote attacker to view arbitrary files outside of the web server path. The issue is due to the ISAPI filter that handles .IDQ files not applying proper sanity checks to URI requests. By appending the CiTemplate variable and specifying a file via a ../.. traversal attack, the server will display any file requested.
|
|
Classification |
Attack Type:
Input Manipulation
|
|
Solution |
Download and install the patch (Q252463i), as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: Configure IDQ files to use specific template files.
|
|
Products |
|
IIS
 |
3.0 |
4.0 |
Index Server
 |
2.0 |
|
|
|
|
Tools & Filters |
|
Nikto
|
516
517
1246
1247
1248
1467
3383
3384
|
|
Nessus
|
10115
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|