vendor:
IIS
by:
SecurityFocus
2.6
CVSS
LOW
Path Disclosure
200
CWE
Product Name: IIS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
htimage.exe Path Disclosure Vulnerability
htimage.exe can be used to determine if a specified path and filename exists on the target host or not. The specified path must be on the same logical drive as the web content. Any file can be specified as an image map in the URL. htimage.exe will then look for that path in the webroot, and then the root of the logical drive containing the webroot. If htimage.exe finds the file, it will generate an error about the file not being a valid image map. Requesting a nonexistent file will return an error message disclosing the actual path of the web root.
Mitigation:
Ensure that htimage.exe is not accessible from the web.