SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/214217 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/3339 | Exploit Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7125 |
Configurations
Information
Published : 2001-09-13 21:00
Updated : 2017-12-18 18:29
NVD link : CVE-2001-0986
Mitre link : CVE-2001-0986
JSON object : View
CWE
Products Affected
microsoft
- index_server