Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:FRONTPAGE:SHTML.EXE-PATH

Severity

Medium

Recommended

No

Category

HTTP

Keywords

Frontpage shtml.exe Path Disclosure

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Frontpage shtml.exe Path Disclosure


This signature detects attempts to reveal the local path of the server using Microsoft IIS 4.0/5.0/FrontPage Server Extensions 1.1 and prior.

Extended Description

The local path of a HTML, HTM, ASP, or SHTML file can be disclosed in Microsoft IIS 4.0/5.0 / Frontpage Server Extensions 1.1 and prior. Passing a path to a non-existent file to the shtml.exe or shtml.dll (depending on platform) program will display an error message stating that the file cannot be found accompanied by the full local path to the web root. For example, performing a request for http://target/_vti_bin/shtml.dll/non_existant_file.html will produce an error message stating "Cannot open "C:\localpath\non_existant_file.html": no such file or folder"

Affected Products

  • Microsoft FrontPage 2000 Server Extensions SR 1.0
  • Microsoft FrontPage Server Extensions Module for Apache 3.0.4
  • Microsoft IIS 4.0
  • Microsoft IIS 5.0

References

  • BugTraq: 1174
  • CVE: CVE-2000-0413
  • URL: http://archives.neohapsis.com/archives/bugtraq/2000-05/0084.html
  • URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2000-0413

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out