vendor:
Internet Information Server (IIS)
by:
Unknown
4.6
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: Internet Information Server (IIS)
Affected Version From: IIS 3.0
Affected Version To: IIS 4.0
Patch Exists: YES
Related CWE: CVE-2000-0523
CPE: a:microsoft:internet_information_server:3.0
Platforms Tested: Windows
2000
Microsoft Internet Information Server (IIS) 3.0 Remote Administration Scripts Information Disclosure Vulnerability
An attacker can remotely access certain scripts in the /scripts/iisadmin directory of Microsoft Internet Information Server (IIS) 3.0, which can lead to the disclosure of sensitive information about the server's directory structure.
Mitigation:
Remove or secure the /scripts/iisadmin directory after upgrading from IIS 3.0 to IIS 4.0.