CVE-1999-1397

Microsoft Index Server 2.0 - Unprotected Physical Path Exposure via AllowedPaths Registry Key

Title source: llm
STIX 2.1

Description

Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.

References (4)

Core 4
Core References
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7559.php
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=92242671024118&w=2
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=92223293409756&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/476

Scores

EPSS 0.1170
EPSS Percentile 95.7%

Details

Status published
Products (1)
microsoft/index_server 2.0
Published Mar 23, 1999
Tracked Since Feb 18, 2026