Vulnerability Development mailing list archives

Re: IIS4.0 .htw vulnerability


From: marc () EEYE COM (Marc)
Date: Mon, 31 Jan 2000 12:43:08 -0800


As the exploit stands now, there is no way to read files from a different
hard drive then the current wwwroot path..

Maybe someone will surprise us though.

Signed,
Marc
eEye Digital Security
http://www.eEye.com

| -----Original Message-----
| From: VULN-DEV List [mailto:VULN-DEV () SECURITYFOCUS COM]On Behalf Of
| Fricke, Gregory D.
| Sent: Friday, January 28, 2000 12:53 PM
| To: VULN-DEV () SECURITYFOCUS COM
| Subject: IIS4.0 .htw vulnerability
|
|
| If the web server is installed on a different partition, i.e. D:, is there
| anyway to view files on the C: drive?
|


Current thread: