Microsoft Windows 2000 Patch: Malformed Hit-highli
Microsoft Windows 2000 Patch: Malformed Hit-highli Ranking & Summary
Microsoft Windows 2000 Patch: Malformed Hit-highli description
When you conduct a search using Indexing Serice, the hit-highlighting function provides search results that highlight portions of documents that satisfy your search query. This vulnerability exists because Indexing Service doesnt set the correct parameters for hit-highlighting search requests. If a malicious user provides a specific type of malformed request, it retrieves files on the server, regardless of the permissions that have been set by the administrator.
By design, the hit-highlighting feature allows the user to specify the name of the document to be hit-highlighted. The user should only be able to request documents within the servers virtual directories; however, if a specific type of malformed argument is provided, it can be used to request a file by its physical location on the drive.
Microsoft Windows 2000 Patch: Malformed Hit-highli Screenshot
Microsoft Windows 2000 Patch: Malformed Hit-highli Keywords
Bookmark Microsoft Windows 2000 Patch: Malformed Hit-highli
Microsoft Windows 2000 Patch: Malformed Hit-highli Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
- Microsoft Exchange 2000 Enterprise Edition Dapi Pa
- Microsoft Exchange 2000 Conferencing Server Setup
- Microsoft Windows 2000 Patch: LSA Memory Loss
- Microsoft Exchange 2000 Server MSN Messenger Servi Update
- Microsoft Excel 2000 Programmatic text export
- Microsoft Outlook 2000 Updated 40- or 56-Bit Encry
- Microsoft Windows 2000 Patch: AOL Image Support
- Microsoft Security Bulletin (MS00-082) 2.0
- Microsoft Internet Explorer HTML Help File Code Execution Vulnerability patch 6-8-2000
- Microsoft WinNT Remote Registry Access Authentication Vulnerability Patch 6-24-2000
- Microsoft Outlook 2000 SR-1 Email security update 6-24-2000
- uCertify PrepKit for Microsoft exam 70-225 6.08.05
- OL2000 Microsoft Outlook 2000 Update
- Microsoft Office 2000 Update SR-2
- Windows 2000 Service Pack 2 Spanish
- Microsoft Office 2000 Service Pack 2 SP-2
- Windows 2000 IrDA Driver Access Violation Patch MS01-046
- Microsoft Greetings 2000 Installer Cleanup Utility
- Microsoft Exchange 2000 Enterprise Edition Outlook
- Microsoft Security Patch Briefing - Home
- Microsoft SQL Server 2000 Patch: Inappropriate Log
- Microsoft Security Bulletin MS01-033
- Microsoft Windows 2000 Patch: No Mapping of Virtua
- Microsoft Windows 2000 Patch: Web Client NTLM Auth