Microsoft IIS 5.0 Translate: f Source Disclosure Vulnerability
According to Security Focus, Microsoft IIS 5.0 has a
dedicated scripting engine for advanced file types which
handles requests for these file types, processes them
accordingly, and then executes them on the server. It is
possible to force the server to send back the source of
known scriptable files to the client. The scripting engine
will be able to locate the requested file, but will not
recognize it as a file that needs to be processed and thus
will send the file source to the client. Microsoft has
issued a patch.
Microsoft IIS 5.0 "Translate: f" Source Disclosure Vulnerability (Security Focus Alert)