vendor:
IIS
by:
SecurityFocus
7.5
CVSS
HIGH
Remote Script Source Disclosure
200
CWE
Product Name: IIS
Affected Version From: 5.1
Affected Version To: 5.1
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:iis:5.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2005
Microsoft IIS Remote Script Source Disclosure Vulnerability
Microsoft IIS is reportedly affected by a remote script source disclosure vulnerability. A successful attack causes the Web server to present the requested file as a plain text file and subsequently disclosing the source. It should be noted that this issue only presents itself when the requested files are stored on a FAT or FAT32 volume and does not arise if the script files are stored on a NTFS volume.
Mitigation:
It is recommended that users upgrade to the latest version of Microsoft IIS to address this issue.