Microsoft IIS 5.0 Translate: f Source Disclosure Vulnerability

 
Aug 14, 2000
According to Security Focus, Microsoft IIS 5.0 has a dedicated scripting engine for advanced file types which handles requests for these file types, processes them accordingly, and then executes them on the server. It is possible to force the server to send back the source of known scriptable files to the client. The scripting engine will be able to locate the requested file, but will not recognize it as a file that needs to be processed and thus will send the file source to the client. Microsoft has issued a patch.

Microsoft IIS 5.0 "Translate: f" Source Disclosure Vulnerability (Security Focus Alert)


Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting