HTR Files Expose ASP File Content on IIS
A malicious user can use this vulnerability to read .asp files.
Steve Manzuik
January 28, 2001
1 Min Read
ReportedJanuary 29, 2001, by Microsoft.
VERSIONS AFFECTED
Internet Information Server 4.0
Internet Information Server 5.0
DESCRIPTION
Microsoft has issued a patch fora new variation of the “File Fragment Reading via .HTR” vulnerability. Amalicious user can use this vulnerability to read .asp files.
VENDOR RESPONSE
Microsoft has released a security bulletin, MS01-004.Microsoftrecommends that users disable .htrfunctionality and not store sensitive information on a Web server.
CREDIT
Discovered byMicrosoft.
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like