Microsoft Windows NT 4.0 Patch: Malformed Hit-high Update
Microsoft Windows NT 4.0 Patch: Malformed Hit-high Update Ranking & Summary
Microsoft Windows NT 4.0 Patch: Malformed Hit-high Update description
When you conduct a search using Indexing Server 2.0, the hit-highlighting function provides search results that highlight portions of documents that satisfy your search query. This vulnerability exists because Indexing Server 2.0 doesnt set the correct parameters for hit-highlighting search requests. If a malicious user provides a specific type of malformed request, it retrieves files on the server, regardless of the permissions that have been set by the administrator.
By design, the hit-highlighting feature allows the user to specify the name of the document to be hit-highlighted. The user should only be able to request documents within the servers virtual directories; however, if a specific type of malformed argument is provided, it can be used to request a file by its physical location on the drive.
For more information about this vulnerability, read Microsoft Security Bulletin MS01-025.
Microsoft Windows NT 4.0 Patch: Malformed Hit-high Update Screenshot
Microsoft Windows NT 4.0 Patch: Malformed Hit-high Update Keywords
Bookmark Microsoft Windows NT 4.0 Patch: Malformed Hit-high Update
Microsoft Windows NT 4.0 Patch: Malformed Hit-high Update Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
- Microsoft Security Patch Briefing - Home
- Microsoft Office 97 Unique Identifier Removal Tool
- Microsoft Visio 2000 Update File Save Improvements
- Microsoft Outlook 2000 SR-1 Update: MultiLanguage Update
- Microsoft Access 2000 Update: SQL Server Readiness
- Microsoft Internet Explorer 5.5 SP1 Security Patch
- Microsoft Windows NT 4.0 Patch: Data Corruption Ac Update
- Microsoft Windows NT 4.0 Patch: IP Fragment Reasse Update
- Microsoft Windows NT 4.0 Service Pack 5 (Intel) with Standard Encryption
- Microsoft Windows NT 4.0 Service Pack 6a (Intel) with Standard Encryption
- CashflowINXL 4.00
- Update for Windows XP Service Pack 2 (KB885222)
- AutoPatcher 2003 May 2007 Core Release
- Microsoft Windows NT 4.0 Service Pack 6a (Alpha) with High Encryption
- Windows NT Registry Permissions Vulnerab 1.0
- Microsoft Windows NT 4.0 Patch: NTLMSSP Privilege Update
- Microsoft Windows NT 4.0 Patch: Index Server Searc Update
- Microsoft Windows NT 4.0 Patch: Multiple NNTP Post Update
- Microsoft Windows NT 4.0 Patch: Print Spooler Secu Update
- Microsoft Windows NT 4.0 Patch: Winsock Mutex Vuln Update
- Microsoft Windows NT 4.0 Patch: Verisign Digital C Update
- Microsoft Windows NT 4.0 Patch: Remote Registry Ac Update
- Microsoft Windows NT 4.0 Patch: FrontPage Server E Update
- Microsoft Windows NT 4.0 Patch: C2 Hotfix Package Update