The CERN Image Map Dispatcher (htimage.exe) in Microsoft FrontPage allows remote attackers to determine the existence, and possibly partial contents, of arbitrary files under the web root via a relative pathname in the PATH_INFO.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/470458/100/0/threaded | mailing list |
http://osvdb.org/42058 | vdb entry |
http://securityreason.com/securityalert/2784 | third party advisory |