FP98: FrontPage 98 Server Extensions DLL Exposes Security Vulnerability (259799)
The information in this article applies to:
- Microsoft FrontPage 98 for Windows
This article was previously published under Q259799 SYMPTOMS
The Dvwssr.dll file, which is included in several Web server products, does not perform access-control checks correctly. Because of this, there is a possibility that a user with Web Authoring permissions on a Web site can view ASP files that belong to other Web sites hosted on the same computer, if that user has read permissions on those files.
NOTE: This problem only occurs on a computer that is running Microsoft Internet Information Server (IIS). This problem does not occur when you run the FrontPage 98 Server Extensions on a UNIX-based Web server.
RESOLUTION
To eliminate this vulnerability, delete all copies of the Dvwssr.dll file from your computer. When you do this, the only functionality that is lost is the ability to generate a link view by using Visual InterDev 1.0. In the FrontPage 98 Server Extensions, the DLL is found in the following location:
_vti_bin\_vti_aut\Dvwssr.dll
Other resolutions for this issue include the following:
- Upgrade to FrontPage 2000 Server Extensions.
- Install Office 2000 Server Extensions.
- Upgrade from Microsoft Windows NT 4.0 Server to Microsoft Windows 2000.
STATUSMicrosoft has confirmed that this is a problem in Microsoft FrontPage 98 for Windows.
Modification Type: | Major | Last Reviewed: | 6/15/2004 |
---|
Keywords: | kbbug kbpending KB259799 |
---|
|