CVE
- Id
- 1991
- CVE No.
- CVE-2000-0413
- Status
- Candidate
- Description
- The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.
- Phase
- Proposed (20000615)
- Votes
- ACCEPT(7) Baker, Cole, Frech, LeBlanc, Levy, Ozancin, Stracener | MODIFY(1) Prosser | NOOP(1) Christey
- Comments
- Prosser> additional source Security BugWare | http://161.53.42.3/~crv/security/bugs/NT/fpse10.html comments on page re: | "MS soon to be released service release OSR 1.2 with needed changes." | I haven"t located anything on MS site yet. Anyone help? | Christey> BID:1433 may also refer to this issue. | Christey> [note to self: review comments by Mark Burnett] | Christey> CHANGEREF XF:iis-shtml-reveal-path XF:frontpage-ext-shtml-path(4439) | LeBlanc> Fixes are up on site now - have been for a while.