<?xml version="1.0" encoding="UTF-8"?>
<osvdb_mangle xml:lang="en" xml:space="preserve" maxVulnId="15276">
	<vuln osvdb_id="1" osvdb_create_date="2002-09-12 09:02:06" last_modified_date="2006-02-14 00:09:39">
		<osvdb_title>ColdFusion exprcalc.cfm OpenFilePath Variable Arbitrary File Disclosure</osvdb_title>
		<disclosure_date>1998-12-25 00:00:00</disclosure_date>
		<discovery_date>1970-01-01 00:00:00</discovery_date>
		<exploit_publish_date>1998-12-25 00:00:00</exploit_publish_date>
		<location_remote>1</location_remote>
		<attack_type_info_disclose>1</attack_type_info_disclose>
		<impact_confidential>1</impact_confidential>
		<exploit_available>1</exploit_available>
		<vuln_verified>1</vuln_verified>
		<vuln_web_check>1</vuln_web_check>
		<products>
			<product affected="Affected">
				<vendor_name>Macromedia, Inc.</vendor_name>
				<base_name>ColdFusion</base_name>
				<version_name>2.0</version_name>
			</product>
			<product affected="Affected">
				<vendor_name>Macromedia, Inc.</vendor_name>
				<base_name>ColdFusion</base_name>
				<version_name>3.0</version_name>
			</product>
			<product affected="Affected">
				<vendor_name>Macromedia, Inc.</vendor_name>
				<base_name>ColdFusion</base_name>
				<version_name>3.1</version_name>
			</product>
			<product affected="Affected">
				<vendor_name>Macromedia, Inc.</vendor_name>
				<base_name>ColdFusion</base_name>
				<version_name>4.0</version_name>
			</product>
		</products>
		<ext_refs>
			<ext_ref type_name="Snort Signature ID" indirect="0">911</ext_ref>
			<ext_ref type_name="CVE ID" indirect="0">1999-0455</ext_ref>
			<ext_ref type_name="Vendor Specific Advisory URL" indirect="0">http://www.macromedia.com/devnet/security/security_zone/asb99-01.html</ext_ref>
			<ext_ref type_name="Bugtraq ID" indirect="0">115</ext_ref>
			<ext_ref type_name="ISS X-Force ID" indirect="0">1740</ext_ref>
			<ext_ref type_name="Generic Exploit URL" indirect="0">http://www.phrack.org/phrack/54/P54-08</ext_ref>
			<ext_ref type_name="Nessus Script ID" indirect="0">10001</ext_ref>
		</ext_refs>
		<credits>
			<credit>
				<author_name>RFP</author_name>
				<author_company>RFP Labs</author_company>
				<author_email>rfp@wiretrip.net</author_email>
				<company_url>http://www.wiretrip.net/rfp</company_url>
			</credit>
		</credits>
		<ext_txts>
			<ext_txt type_name="Solution Description" language="English" revision="1">
				<text>Upgrade to version 4.0.1 or higher, as it has been reported to fix this vulnerability.  It is also possible to correct the flaw by removing all sample code and documentation from the server.</text>
			</ext_txt>
			<ext_txt type_name="Vulnerability Description" language="English" revision="2">
				<text>ColdFusion contains a flaw that may lead to an unauthorized information disclosure.  The issue is triggered when an attacker specifies the OpenFilePath variable in the Expression Evaluator.  This allows an attacker to view the contents of arbitrary files on the server and may result in a loss of confidentiality.</text>
			</ext_txt>
			<ext_txt type_name="Manual Testing Notes" language="English" revision="1">
				<text>http://[target]/cfdocs/expeval/exprcalc.cfm?OpenFilePath=c:\boot.ini</text>
			</ext_txt>
			<ext_txt type_name="Short Description" language="English" revision="3">
				<text>ColdFusion 4.0 ExprCalc.cfm Arbitrary File Read</text>
			</ext_txt>
		</ext_txts>
		<scores>
		</scores>
	</vuln>
	<vuln osvdb_id="2" osvdb_create_date="2002-09-12 09:02:06" last_modified_date="2006-02-14 00:22:17">
		<osvdb_title>Microsoft IIS ExAir search.asp Direct Request DoS</osvdb_title>
		<disclosure_date>1999-01-26 00:00:00</disclosure_date>
		<discovery_date>1970-01-01 00:00:00</discovery_date>
		<exploit_publish_date>1999-01-26 00:00:00</exploit_publish_date>
		<location_remote>1</location_remote>
		<attack_type_dos>1</attack_type_dos>
		<impact_available>1</impact_available>
		<exploit_available>1</exploit_available>
		<vuln_verified>1</vuln_verified>
		<vuln_web_check>1</vuln_web_check>
		<products>
			<product affected="Affected">
				<vendor_name>Microsoft Corporation</vendor_name>
				<base_name>IIS</base_name>
				<version_name>4.0</version_name>
			</product>
		</products>
		<ext_refs>
			<ext_ref type_name="CVE ID" indirect="0">1999-0449</ext_ref>
			<ext_ref type_name="Bugtraq ID" indirect="0">193</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1500</ext_ref>
			<ext_ref type_name="ISS X-Force ID" indirect="0">2229</ext_ref>
			<ext_ref type_name="Nessus Script ID" indirect="0">10004</ext_ref>
			<ext_ref type_name="Mail List Post" indirect="0">http://archives.neohapsis.com/archives/bugtraq/1999_1/0336.html</ext_ref>
		</ext_refs>
		<credits>
			<credit>
				<author_name>David Litchfield</author_name>
				<author_company>Personal Page</author_company>
				<author_email>mnemonix@GLOBALNET.CO.UK</author_email>
				<company_url>http://www.infowar.co.uk/mnemonix/</company_url>
			</credit>
		</credits>
		<ext_txts>
			<ext_txt type_name="Solution Description" language="English" revision="2">
				<text>Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: Delete the sample scripts from the web server, or restrict access to them.</text>
			</ext_txt>
			<ext_txt type_name="Vulnerability Description" language="English" revision="3">
				<text>Microsoft IIS contains a flaw that allows a remote attacker to cause a denial of service. The issue is due to the presence of a default script (search.asp) of a sample site named &amp;quot;ExAir&amp;quot;. If the script is called without having the proper DLL files running, it will cause the server CPU to increase to 100% usage.</text>
			</ext_txt>
			<ext_txt type_name="Manual Testing Notes" language="English" revision="1">
				<text>http://[target]/iissamples/exair/search/search.asp</text>
			</ext_txt>
			<ext_txt type_name="Short Description" language="English" revision="1">
				<text>Microsoft IIS 4.0 ExAir search.asp DoS</text>
			</ext_txt>
		</ext_txts>
		<scores>
		</scores>
	</vuln>
	<vuln osvdb_id="3" osvdb_create_date="2002-09-12 09:02:06" last_modified_date="2006-02-14 00:18:13">
		<osvdb_title>Microsoft IIS ExAir query.asp Direct Request DoS</osvdb_title>
		<disclosure_date>1999-01-26 00:00:00</disclosure_date>
		<discovery_date>1970-01-01 00:00:00</discovery_date>
		<exploit_publish_date>1999-01-26 00:00:00</exploit_publish_date>
		<location_remote>1</location_remote>
		<attack_type_dos>1</attack_type_dos>
		<impact_available>1</impact_available>
		<exploit_available>1</exploit_available>
		<vuln_verified>1</vuln_verified>
		<vuln_web_check>1</vuln_web_check>
		<products>
			<product affected="Affected">
				<vendor_name>Microsoft Corporation</vendor_name>
				<base_name>IIS</base_name>
				<version_name>4.0</version_name>
			</product>
		</products>
		<ext_refs>
			<ext_ref type_name="CVE ID" indirect="0">1999-0449</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1028</ext_ref>
			<ext_ref type_name="Bugtraq ID" indirect="0">193</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1500</ext_ref>
			<ext_ref type_name="ISS X-Force ID" indirect="0">2229</ext_ref>
			<ext_ref type_name="Nessus Script ID" indirect="0">10003</ext_ref>
			<ext_ref type_name="Mail List Post" indirect="0">http://archives.neohapsis.com/archives/bugtraq/1999_1/0336.html</ext_ref>
		</ext_refs>
		<credits>
			<credit>
				<author_name>David Litchfield</author_name>
				<author_company>Personal Page</author_company>
				<author_email>mnemonix@GLOBALNET.CO.UK</author_email>
				<company_url>http://www.infowar.co.uk/mnemonix/</company_url>
			</credit>
		</credits>
		<ext_txts>
			<ext_txt type_name="Solution Description" language="English" revision="1">
				<text>Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: Delete the sample scripts from the web server, or restrict access to them.</text>
			</ext_txt>
			<ext_txt type_name="Vulnerability Description" language="English" revision="1">
				<text>Microsoft IIS contains a flaw that allows a remote attacker to cause a denial of service. The issue is due to the presence of a default script (query.asp) of a sample site named &amp;quot;ExAir&amp;quot;. If the script is called without having the proper DLL files running, it will cause the server CPU to increase to 100% usage.</text>
			</ext_txt>
			<ext_txt type_name="Manual Testing Notes" language="English" revision="2">
				<text>http://[victim]/iissamples/exair/search/query.asp</text>
			</ext_txt>
			<ext_txt type_name="Short Description" language="English" revision="1">
				<text>Microsoft IIS 4.0 ExAir query.asp Direct Request DoS</text>
			</ext_txt>
		</ext_txts>
		<scores>
		</scores>
	</vuln>
	<vuln osvdb_id="4" osvdb_create_date="2002-09-12 09:02:06" last_modified_date="2006-02-14 00:21:42">
		<osvdb_title>Microsoft IIS ExAir advsearch.asp Direct Request DoS</osvdb_title>
		<disclosure_date>1999-01-26 00:00:00</disclosure_date>
		<discovery_date>1970-01-01 00:00:00</discovery_date>
		<exploit_publish_date>1999-01-26 00:00:00</exploit_publish_date>
		<location_remote>1</location_remote>
		<attack_type_dos>1</attack_type_dos>
		<impact_available>1</impact_available>
		<exploit_available>1</exploit_available>
		<vuln_verified>1</vuln_verified>
		<vuln_web_check>1</vuln_web_check>
		<products>
			<product affected="Affected">
				<vendor_name>Microsoft Corporation</vendor_name>
				<base_name>IIS</base_name>
				<version_name>4.0</version_name>
			</product>
		</products>
		<ext_refs>
			<ext_ref type_name="CVE ID" indirect="0">1999-0449</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1028</ext_ref>
			<ext_ref type_name="Bugtraq ID" indirect="0">193</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1500</ext_ref>
			<ext_ref type_name="Other Advisory URL" indirect="0">http://archives.neohapsis.com/archives/bugtraq/1999_1/0336.html</ext_ref>
			<ext_ref type_name="ISS X-Force ID" indirect="0">2229</ext_ref>
			<ext_ref type_name="Nessus Script ID" indirect="0">10002</ext_ref>
		</ext_refs>
		<credits>
			<credit>
				<author_name>David Litchfield</author_name>
				<author_company>Personal Page</author_company>
				<author_email>mnemonix@GLOBALNET.CO.UK</author_email>
				<company_url>http://www.infowar.co.uk/mnemonix/</company_url>
			</credit>
		</credits>
		<ext_txts>
			<ext_txt type_name="Solution Description" language="English" revision="1">
				<text>Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: Delete the sample scripts from the web server, or restrict access to them.</text>
			</ext_txt>
			<ext_txt type_name="Vulnerability Description" language="English" revision="1">
				<text>Microsoft IIS contains a flaw that allows a remote attacker to cause a denial of service. The issue is due to the presence of a default script (advsearch.asp) of a sample site named &amp;quot;ExAir&amp;quot;. If the script is called without having the proper DLL files running, it will cause the server CPU to increase to 100% usage.</text>
			</ext_txt>
			<ext_txt type_name="Manual Testing Notes" language="English" revision="1">
				<text>http://[target]/iissamples/exair/search/advsearch.asp</text>
			</ext_txt>
			<ext_txt type_name="Short Description" language="English" revision="1">
				<text>Microsoft IIS 4.0 ExAir advsearch.asp Direct Request DoS</text>
			</ext_txt>
		</ext_txts>
		<scores>
		</scores>
	</vuln>
	<vuln osvdb_id="7" osvdb_create_date="2002-09-12 09:02:06" last_modified_date="2006-02-14 00:24:46">
		<osvdb_title>Microsoft IIS / Site Server showcode.asp source Variable Traversal Arbitrary File Access</osvdb_title>
		<disclosure_date>1999-05-07 00:00:00</disclosure_date>
		<discovery_date>1970-01-01 00:00:00</discovery_date>
		<exploit_publish_date>1999-05-07 00:00:00</exploit_publish_date>
		<location_remote>1</location_remote>
		<attack_type_info_disclose>1</attack_type_info_disclose>
		<impact_confidential>1</impact_confidential>
		<exploit_available>1</exploit_available>
		<vuln_verified>1</vuln_verified>
		<vuln_web_check>1</vuln_web_check>
		<products>
			<product affected="Affected">
				<vendor_name>Microsoft Corporation</vendor_name>
				<base_name>Site Server</base_name>
				<version_name>3.0</version_name>
			</product>
			<product affected="Affected">
				<vendor_name>Microsoft Corporation</vendor_name>
				<base_name>Internet Information Server</base_name>
				<version_name>4.0</version_name>
			</product>
		</products>
		<ext_refs>
			<ext_ref type_name="CVE ID" indirect="0">1999-0736</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1032</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1033</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1034</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1035</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1036</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1037</ext_ref>
			<ext_ref type_name="CIAC Advisory" indirect="0">k-068</ext_ref>
			<ext_ref type_name="Vendor URL" indirect="0">http://www.microsoft.com/</ext_ref>
			<ext_ref type_name="Microsoft Security Bulletin" indirect="0">MS99-013</ext_ref>
			<ext_ref type_name="Nessus Script ID" indirect="0">10007</ext_ref>
			<ext_ref type_name="Bugtraq ID" indirect="0">0167</ext_ref>
			<ext_ref type_name="Microsoft Knowledge Base Article" indirect="0">232449</ext_ref>
			<ext_ref type_name="Other Advisory URL" indirect="0">http://www.atstake.com/research/advisories/1999/showcode.txt</ext_ref>
			<ext_ref type_name="Related OSVDB ID" indirect="0">474</ext_ref>
			<ext_ref type_name="Related OSVDB ID" indirect="0">782</ext_ref>
			<ext_ref type_name="Related OSVDB ID" indirect="0">15749</ext_ref>
			<ext_ref type_name="Snort Signature ID" indirect="0">1404</ext_ref>
			<ext_ref type_name="ISS X-Force ID" indirect="0">2381</ext_ref>
		</ext_refs>
		<credits>
			<credit>
				<author_name>Parcens</author_name>
				<author_company></author_company>
				<author_email></author_email>
				<company_url></company_url>
			</credit>
		</credits>
		<ext_txts>
			<ext_txt type_name="Solution Description" language="English" revision="1">
				<text>Microsoft has released a patch to address this vulnerability.  It is also possible to correct the flaw by implementing the following workaround: Remove the /IISSamples virtual directory when not needed. As a general rule, do not install sample scripts or sample applications on a production server.</text>
			</ext_txt>
			<ext_txt type_name="Vulnerability Description" language="English" revision="1">
				<text>Microsoft IIS and Site Server contains a flaw that allows a remote attacker to arbitrary access files outside of the web path. The issue is due to the &amp;#39;showcode.asp&amp;#39; script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the &amp;#39;source&amp;#39; variable.</text>
			</ext_txt>
			<ext_txt type_name="Manual Testing Notes" language="English" revision="1">
				<text>http://[victim]/pathto/showcode.asp?source=../../../../../../boot.ini</text>
			</ext_txt>
			<ext_txt type_name="Short Description" language="English" revision="3">
				<text>Microsoft IIS 4.0 / Site Server 3.0 showcode.asp source Variable Traversal Arbitrary File Access</text>
			</ext_txt>
		</ext_txts>
		<scores>
		</scores>
	</vuln>