HTTP: Microsoft FrontPage XML Information Disclosure

This signature detects attempts to exploit a known vulnerability against Microsoft FrontPage. A successful attack can lead to unauthorized information disclosure.

Extended Description

Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a FrontPage document, aka "XML Disclosure Vulnerability."

Affected Products

Microsoft frontpage

References

CVE: CVE-2013-3137

Short Name
HTTP:STC:MS-FRONTPAGE-INFO-DISC
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2013-3137 Disclosure FrontPage Information Microsoft XML
Release Date
09/10/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

4.3

Found a potential security threat?