First published: Wed Jan 26 2000(Updated: )
Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Index Server | =2.0 | |
=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0098 is considered to be of moderate severity as it allows attackers to gain information about the directory structure.
To fix CVE-2000-0098, update Microsoft Index Server to the latest version or apply the Microsoft security patch as detailed in security updates.
CVE-2000-0098 affects Microsoft Index Server version 2.0.
Yes, CVE-2000-0098 can potentially lead to further attacks by disclosing directory paths which can be exploited.
CVE-2000-0098 can disclose the real path of web directories, which can inform attackers about the server's file structure.