5
CVSSv2

CVE-1999-0278

Published: 01/06/1998 Updated: 12/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft internet information server 3.0

microsoft internet information server 4.0

microsoft windows nt 4.0

Exploits

source: wwwsecurityfocuscom/bid/149/info Microsoft IIS and other NT webservers contain a vulnerability that allows remote users to obtain the source code for an ASP file When one appends ::$DATA to an asp being requested, the ASP source will be returned, instead of executing the ASP For example: xyz/myaspasp::$DATA will return t ...

Github Repositories

snortsig A read-only (for now) interface to snort signatures using pyparsing on the back end You can parse signatures from multiple files, or just via a string Once parsed, you can use the search() method to retrieve signatures with specific attributes Known Bugs snortsig currently doesn't deal well with escaped semi-colons snortsig currently doesn't deal well