Short Name |
HTTP:IIS:IISAPI-EXT-PATH-DISC |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
HTTP |
Keywords |
IIS IISAPI Extension Enumerate Root Web Server Directory Path Disclosure |
Release Date |
2012/11/28 |
Update Number |
2206 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Internet Information Services(IIS) version 5.0 and earlier. A successful attack can lead to unauthorized path disclosure. This is an old issue and newer versions of IIS are unaffected by this vulnerability.
A GET request that specifies a nonexistent file with an IISAPI-registered extension (ie .pl, .idq) will cause the IIS server to return an error message that includes the full path of the root web server directory. This can happen if the file is referenced as the target of the GET or passed in a variable to a script that looks for the file. Example: CGI Error The specified CGI application misbehaved by not returning a complete set of HTTP headers. The headers it did return are: Can't open perl script "C:\InetPub\scripts\ bogus.pl": No such file or directory