The (a) Quick n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Baby_asp_web_server | Pablo_software_solutions | 2.7.2 (including) | 2.7.2 (including) |
Quick_and_easy_web_server | Pablo_software_solutions | 3.0.6 (including) | 3.0.6 (including) |
Quick_and_easy_web_server | Pablo_software_solutions | 3.1.0 (including) | 3.1.0 (including) |