The information in this article applies to:
SYMPTOMS
Users running FrontPage Personal Web Server 1.0 (vhttpd32.exe version 3.0.2.xxxx) under the Microsoft Windows 95 or Windows 98 operating systems are vulnerable to unauthorized users accessing their files using a specific non-standard URL. The unauthorized users would have to know the exact file name to access it. CAUSEThis vulnerability involves the ability of a malicious user to bypass the server's normal file access controls by entering a non-standard URL. The file must be specifically requested by name, so the malicious user would need to already know the name of the file or correctly guess it. The vulnerability only affects users of FrontPage Personal Web Server 1.0 (vhttpd32.exe version 3.0.2.xxxx) to host their own Web site. RESOLUTION
A fully supported patch is available to fix this vulnerability, and Microsoft recommends that affected customers download and install it. http://officeupdate.microsoft.com/Articles/PersWeb.htm Additional query words: front page fix add-on add on update
Keywords : kbdta |
Last Reviewed: March 25, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |