Vulnerabilities > CVE-1999-0450 - Unspecified vulnerability in Microsoft products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | Microsoft IIS 5.0 IISAPI Extension Enumerate Root Web Server Directory Vulnerability. CVE-1999-0450. Remote exploit for windows platform |
id | EDB-ID:19152 |
last seen | 2016-02-02 |
modified | 1999-01-26 |
published | 1999-01-26 |
reporter | Mnemonix |
source | https://www.exploit-db.com/download/19152/ |
title | Microsoft IIS 5.0 IISAPI Extension Enumerate Root Web Server Directory Vulnerability |
Nessus
NASL family | Web Servers |
NASL id | IIS_PERL_PROBLEM.NASL |
description | It was possible to obtain the physical location of a virtual web directory of this host by issuing a request for a non-existent file with an IISAPI-registered extension. An attacker may use this flaw to gain more information about the remote host, and hence make more focused attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10120 |
published | 1999-06-22 |
reporter | This script is Copyright (C) 1999-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10120 |
title | Microsoft IIS perl.exe HTTP Path Disclosure |
code |
|