Search:     Advanced search
server monitoring

shtml.exe reveals full path

Article ID: 10405
Last updated: 27 Jan, 2009
Views: 427
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

shtml.exe reveals full path

This script is Copyright (C) 2000 Renaud Deraison

FamilyWeb Servers
Plugin ID10405
Bugtraq ID1174
CVE IDCVE-2000-0413

Description:

The shtml.exe CGI which comes with FrontPage 2000
reveals the full path to the remote web root when
it is given a non-existent file as an argument.

This is useful to an attacker who can gain more
knowledge against the remote host.

Solution : Install Windows 2000 SP3
Risk factor : Low
This article was:   Helpful | Not Helpful
Prev   Next
Apache < 2.0.47 Multiple Vulnerabilities     Microsoft .NET Handlers Enumeration