First published: Fri Mar 31 2000(Updated: )
Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Index Server | =2.0 | |
=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0302 has a moderate severity level due to the potential exposure of sensitive ASP source code.
CVE-2000-0302 allows remote attackers to access and view the source code of ASP files, leading to potential information leakage.
To mitigate CVE-2000-0302, users should disable the CiWebHitsFile functionality or update to a secure version of Microsoft Index Server.
CVE-2000-0302 specifically affects Microsoft Index Server version 2.0.
A possible workaround for CVE-2000-0302 is to restrict access to the null.htw URL and keep sensitive files outside the web root.