HTR Files Expose ASP File Content on IIS

A malicious user can use this vulnerability to read .asp files.

Steve Manzuik

January 28, 2001

1 Min Read
ITPro Today logo

ReportedJanuary 29, 2001, by Microsoft.

VERSIONS AFFECTED

  • Internet Information Server 4.0

  • Internet Information Server 5.0 

DESCRIPTION

Microsoft has issued a patch fora new variation of the “File Fragment Reading via .HTR” vulnerability. Amalicious user can use this vulnerability to read .asp files.

VENDOR RESPONSE

Microsoft has released a security bulletin, MS01-004.Microsoftrecommends that users disable .htrfunctionality and not store sensitive information on a Web server.

CREDIT
Discovered byMicrosoft.

 

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like