7.5
CVSSv2

CVE-1999-0450

Published: 26/01/1999 Updated: 23/11/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet information server 3.0

microsoft internet information services 5.0

microsoft internet information services 2.0

microsoft internet information server 4.0

Exploits

source: wwwsecurityfocuscom/bid/194/info A GET request that specifies a nonexistent file with an IISAPI-registered extension (ie pl, idq) will cause the IIS server to return an error message that includes the full path of the root web server directory This can happen if the file is referenced as the target of the GET or passed in a va ...