CVE Vulnerabilities

CVE-1999-1397

Published: Mar 23, 1999 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndexCatalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.

Affected Software

Name Vendor Start Version End Version
Index_server Microsoft 2.0 (including) 2.0 (including)

References