Vulnerabilities > CVE-1999-0253 - Unspecified vulnerability in Microsoft products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
nessus

Summary

IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.

Nessus

NASL familyWeb Servers
NASL idASP_SOURCE_DOT.NASL
descriptionIt is possible to get the source code of a remote ASP script by appending
last seen2020-06-01
modified2020-06-02
plugin id10363
published2000-04-10
reporterThis script is Copyright (C) 2000-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10363
titleMicrosoft IIS/PWS %2e Request ASP Source Disclosure