CVE-1999-1397
high · 7.5Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.
7.5
CVSS
11.7%
EPSS (exploit prob.)
96th
EPSS percentile
1999-03-23
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | index_server | 2.0 |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=92242671024118&w=2
- http://marc.info/?l=ntbugtraq&m=92223293409756&w=2
- http://www.iss.net/security_center/static/7559.php
- http://www.securityfocus.com/bid/476
- http://marc.info/?l=bugtraq&m=92242671024118&w=2
- http://marc.info/?l=ntbugtraq&m=92223293409756&w=2
- http://www.iss.net/security_center/static/7559.php
- http://www.securityfocus.com/bid/476
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-1999-1397