Version: 2008
advertisement
Click Here

IIS4 Absent Directory Browser Argument Vulnerability Patch

  • Quick specs
  • Price: Free
  • Operating system: Windows 95/98/2000/NT
  • Date added: July 21, 2000
  • Total Downloads: 7,158
  • Downloads last week: 20
  • See full specifications
Add to my list Add to my Watch List

A newer version of IIS4 Absent Directory Browser Argument Vulnerability Patch is available.

(Download doesn't provide access to previous versions of this program.)

Publisher's description

From Microsoft :

From the developer:

"There are two vulnerabilities at issue:

  • The 'Absent Directory Browser Argument' vulnerability. An administrative script installed as part of IIS 3.0 but preserved on upgrade to IIS 4.0 or IIS 5.0 does not correctly handle the case where an expected argument is missing. The absence of the argument causes the script to go into an infinite loop, at which point the script consumes all CPU resources on the server. In addition, the permissions on this tool and several related ones, which were appropriate under IIS 3.0, are inappropriate under IIS 4.0 and 5.0. This could allow web site visitors to use these tools, which provide the ability to view the directory structure on the server.

  • A new variant on the 'File Fragment Reading via .HTR' vulnerability. The original version of this vulnerability was discussed in Microsoft Security Bulletin MS00-031. The new vulnerability differs only in the specific way that it could be exploited – like the original version, the effect of the vulnerability is that fragments of .ASP and other files could potentially be retrieved from the server. As in the original version, the mechanics of the new variant make it likely that the parts of an .ASP file most interesting to a malicious user would be stripped out.
Microsoft has released this patch which eliminates both of these vulnerabilities."

Note: The patch should only be installed by customers who have a business-critical need for the .HTR functionality. Microsoft recommends that all other customers disable the .HTR functionality altogether, as discussed in the FAQ. Customers who choose to install the patch should also strengthen the permissions on the /scripts/iisadmin folder in each web site on the server, and ensure that only administrators can access it.

Test drive Windows 7, Windows Server 2008 R2 and Exchange Server 2010

More popular Encryption Software downloads

  1. 90,350 downloads 1. RoboForm
  2. 38,190 downloads 2. Hotspot Shield
  3. 31,064 downloads 3. Computer Use Reporter
  4. 7,159 downloads 4. Easy Private Disk
  5. 6,478 downloads 5. Easy File Encryption
  6. See all Encryption Software downloads
Get the scoop on what you need to secure your PC.

User reviews of IIS4 Absent Directory Browser Argument Vulnerability Patch

Write your own review Be the first one to review IIS4 Absent Directory Browser Argument Vulnerability Patch and share your experience with the CNET community!
Previous versions: See all user reviews

Submit your review

Log in or create an account to submit your review for:

IIS4 Absent Directory Browser Argument Vulnerability Patch

ORLog in with your Facebook account
1. Rate this product:
(Mouse over the stars to rate this product and click to set your rating.)
2. One-line summary:(Summarize your review in one line. 10 characters minimum; required.)
0 of 55 characters
3. Pros:(Tell us what you like about this product. 10 characters minimum; required.)
0 of 250 characters
4. Cons:(Tell us what you don't like about this product. 10 characters minimum; required.)
0 of 250 characters
Bottom-line summary:(Explain to us in detail why you like or dislike the product, focusing your comments on the product's features and functionality, and your experience using the product. This field is optional.)
0 of 5000 characters

The posting of advertisements, profanity, or personal attacks are prohibited.
Click here to review our site terms of use.

Submit

Previous Versions:


advertisement
Click Here