Description
Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /_vti_pvt/botinfs.cnf, (3) /_vti_pvt/bots.cnf, or (4) /_vti_pvt/linkinfo.cnf.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Google Map Cross-Site Scripting (1.1.4)
ReviveAdserver Improper Authentication Vulnerability (CVE-2016-9124)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1591)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2531)