SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#910624

Microsoft Windows 2000 Indexing Service permits read access to files outside web root via crafted request

Overview

A vulnerability exists in the way that Index Server 2.0 and the Indexing Service for Windows 2000 handles search requests. This vulnerability may alllow attackers to view the contents of "include" files located on the web server.

I. Description

By submitting a specific search request to a system running Index Server 2.0 or Indexing Service for Windows 2000, a remote attacker may be able to read the contents of "include" files located on the server. While "include" files should not contain sensitive information, if they did, this vulnerability might expose that data to attackers.

This vulnerability is a variant of the problem described in Microsoft Security Bulletin MS00-006.

II. Impact

A remote attacker can view the contents of "include" files located on a vulnerable web server.

III. Solution

Apply a Patch


Microsoft has published patches correcting this vulnerability. The patches are listed in their advisory at:


Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable16-Jul-2002

References

http://www.microsoft.com/technet/security/bulletin/MS01-025.asp
http://www.securityfocus.com/bid/2709

Credit

Thanks to David Litchfield of @Stake for discovering this vulnerability.

This document was written by Cory F. Cohen.

Other Information

Date Public:2001-05-10
Date First Published:2002-09-27
Date Last Updated:2002-09-27
CERT Advisory: 
CVE-ID(s):CAN-2001-0245
NVD-ID(s):CAN-2001-0245
US-CERT Technical Alerts: 
Severity Metric:3.83
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get a PDF Reader