First published: Mon Jun 01 1998(Updated: )
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =3.0 | |
Microsoft Internet Information Services | =4.0 | |
Microsoft Windows NT | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0278 is considered a critical vulnerability due to the potential for remote attackers to access sensitive source code.
To fix CVE-1999-0278, you should apply the relevant security patch provided by Microsoft for Internet Information Server 3.0 or 4.0.
CVE-1999-0278 affects Microsoft Internet Information Server versions 3.0 and 4.0, as well as Windows NT 4.0.
Yes, CVE-1999-0278 can lead to data leakage as it allows attackers to retrieve source code from ASP files.
Running IIS 3.0 or 4.0 without applying the security updates for CVE-1999-0278 poses significant security risks.