First published: Thu Feb 03 2000(Updated: )
Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office FrontPage | =98 | |
Microsoft Office FrontPage | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0122 is considered a medium severity vulnerability as it allows remote attackers to disclose sensitive information.
To mitigate CVE-2000-0122, users should upgrade to a non-vulnerable version of Microsoft FrontPage or disable the htimage.exe script.
CVE-2000-0122 affects Microsoft FrontPage versions 98 and 2000.
The impact of CVE-2000-0122 is that it allows remote attackers to determine the physical path of a virtual directory.
Yes, there are public exploits available that demonstrate the ability to enumerate the physical paths of directories through CVE-2000-0122.