IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. An attacker may use this flaw to gain more information about the remote host, and hence make more focused attacks.
Select 'Preferences ->Home directory ->Application', and check the checkbox 'Check if file exists' for the ISAPI mappings of your server.
- IBM WebSphere Application Server (WAS) Security Bypass Vulnerability
- Cross-Site Scripting in Cherokee Error Pages
- IBM HTTP Server Multiple Cross Site Scripting Vulnerabilities
- Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
- IBM WebSphere Application Server (WAS) Security Bypass Vulnerability - March 2011