HTTP: Microsoft IIS UNC Path Disclosure Vulnerability
This signature detects attempts to exploit a known vulnerability against Microsoft IIS. Attackers can bypass security restrictions and obtain the real pathname of the document root by requesting non-existent files with .ida, .idq or .htx extensions.
Extended Description
IDQ, IDA, and HTX files cannot be served from a network share. If a website is set up in this manner, and a user clicks on a link that links to one of these files, the share path will be disclosed to the user in the resulting error message.
Affected Products
Microsoft iis
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Microsoft
5.0