Microsoft IIS CodeBrws.ASP File...

- AV AC AU C I A
发布: 2002-04-18
修订: 2025-04-13

Microsoft IIS 5.0 ships with a sample script that may be used to view the source code of other scripts in the sample scripts (/IISSAMPLES) directory. This script is designed to only display files with a .html, .htm, .asp or .inc extension. However, a flaw exists which will allow an additional character to be added to the file extension. This may allow an attacker to view, for example, .aspx files used by the .NET architecture. If used in conjunction with the issues discussed in BID 4525, this may expose files outside of the sample script directory.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息