5
CVSSv2

CVE-2000-0302

Published: 31/03/2000 Updated: 12/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Microsoft Index Server allows remote malicious users to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft index server 2.0

Exploits

source: wwwsecurityfocuscom/bid/1084/info Index Server can be used to cause IIS to display the source of asp and possibly other server-side processed files By appending a space (%20) to the end of the filename specified in the 'CiWebHitsFile' variable, and setting 'CiHiliteType' to 'Full' and 'CiRestriction' to 'None', it is possible t ...