Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claimed using an HTTP request for colegal.htm that contains .. (dot dot) sequences.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/1/256125 | broken link mailing list |
http://www.securityfocus.com/bid/4084 | third party advisory vdb entry |
http://online.securityfocus.com/archive/1/255555 | broken link mailing list |