IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Internet_information_server |
Microsoft |
3.0 |
3.0 |
Internet_information_services |
Microsoft |
2.0 |
2.0 |
References