CVE

Id
1731  
CVE No.
CVE-2000-0153  
Status
Candidate  
Description
FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.  
Phase
Proposed (20000223)  
Votes
ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) LeBlanc  
Comments
LeBlanc> I think this is the same as | http://www.microsoft.com/technet/security/bulletin/ms99-010.asp | If that is true, and you already have it logged, we don"t want to have an | entry for the same bug. | Christey> MS:MS99-010 describes CVE-1999-0386. Are there sufficient | details to ensure that this is the same problem? | | See http://www.securityfocus.com/templates/archive.pike?list=1&msg=01bae51a$9ab232b0$0100007f@nordnode | | Frech> XF:pws-file-access | (We currently have this issue assigned to this CAN and to CVE-1999-0386. I | see that others have similar concerns that this is a duplicate; please | confirm on current status of this candidate.) | Christey> [note to self: review comments by Mark Burnett]