Vulnerabilities > CVE-1999-0386 - Unspecified vulnerability in Microsoft Frontpage and Personal web Server

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
microsoft
nessus
exploit available

Summary

Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Exploit-Db

descriptionMS FrontPage Personal WebServer 1.0/Personal Web Server 4.0 Directory Traversal. CVE-1999-0386. Remote exploit for windows platform
idEDB-ID:19753
last seen2016-02-02
modified1996-01-17
published1996-01-17
reporterkiborg
sourcehttps://www.exploit-db.com/download/19753/
titleMicrosoft frontpage personal webserver 1.0/personal Web server 4.0 - Directory Traversal

Nessus

NASL familyCGI abuses
NASL idMSPWS_DOTDOTDOT.NASL
descriptionIt is possible to read any file on the remote system by prepending several dots before the file name.
last seen2020-06-01
modified2020-06-02
plugin id10142
published1999-06-22
reporterThis script is Copyright (C) 1999-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10142
titleMicrosoft Personal Web Server Multiple Dot Request Arbitrary File Access