First published: Fri Dec 31 1999(Updated: )
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =3.0 | |
Microsoft Internet Information Services (IIS) | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-1999-0154 is considered to be high due to the potential for remote attackers to exploit the vulnerability.
To fix CVE-1999-0154, upgrade to a later version of Internet Information Server that does not allow for source code exposure.
CVE-1999-0154 affects Microsoft Internet Information Server versions 2.0 and 3.0.
CVE-1999-0154 can be exploited by remote attackers to access and read the source code of ASP pages.
CVE-1999-0154 is classified as a remote vulnerability, as it can be exploited over the network.