[Full-disclosure] IIS 5.1 Source Disclosure Under FAT/FAT32 Volumes Using WebDAV

2005-09-07 Thread Jerome Athias
It is possible to remotely view the source code of web script files though a specially crafted WebDAV HTTP request. Only IIS 5.1 seems to be vulnerable. The web script file must be on a FAT or a FAT32 volume, web scripts located on a NTFS are not vulnerable. The information has been provided by In

Re: [Full-disclosure] IIS 5.1 Source Disclosure Under FAT/FAT32 Volumes Using WebDAV

2005-09-10 Thread security curmudgeon
Hi Jerome, : It is possible to remotely view the source code of web script files : though a specially crafted WebDAV HTTP request. Only IIS 5.1 seems to be : vulnerable. The web script file must be on a FAT or a FAT32 volume, web : scripts located on a NTFS are not vulnerable. : : The informa