HTTP: Microsoft Index Server WebHits ISAPI filter Information Disclosure

There exists a vulnerability in Microsoft Index Server. Successful exploitation allows remote attackers to read arbitrary files.

Extended Description

The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.

Affected Products

Microsoft index_server

References

CVE: CVE-2000-0097

Short Name
HTTP:MISC:INDEX-WEBHITS-ISAPI
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2000-0097 Disclosure ISAPI Index Information Microsoft Server WebHits filter
Release Date
11/22/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

5.0

Found a potential security threat?