Title: Microsoft IIS Translate f: Request ASP Source Disclosure
Info
Disclosure
Aug 15, 2000
Discovery
Unknown
Dates
Exploit
Aug 16, 2000
Solution
Aug 14, 2000
Description
Microsoft IIS contains a flaw that may allow a remote attacker to view the source code of ASP/ASA scripts. The issue is due to the server not properly handling the "Translate: f" header, used by WebDAV and FrontPage2000. With a specially crafted header, an attacker can force the server to display script source code instead of processing the script normally. This may reveal sensitive information such as internal IP addresses, account names or passwords.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
OSVDB Verified,
Vendor Verified,
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch (MS00-058) to address this vulnerability.