|
|
|
![]() |
Vulnerability Note VU#910624Microsoft Windows 2000 Indexing Service permits read access to files outside web root via crafted requestOverviewA vulnerability exists in the way that Index Server 2.0 and the Indexing Service for Windows 2000 handles search requests. This vulnerability may alllow attackers to view the contents of "include" files located on the web server.I. DescriptionBy submitting a specific search request to a system running Index Server 2.0 or Indexing Service for Windows 2000, a remote attacker may be able to read the contents of "include" files located on the server. While "include" files should not contain sensitive information, if they did, this vulnerability might expose that data to attackers.This vulnerability is a variant of the problem described in Microsoft Security Bulletin MS00-006.
Systems Affected
Referenceshttp://www.microsoft.com/technet/security/bulletin/MS01-025.asp Thanks to David Litchfield of @Stake for discovering this vulnerability. This document was written by Cory F. Cohen.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||