CVE-1999-0253

3 documents3 sources
Severity
7.5HIGH
EPSS
3.0%
top 13.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 1
Latest updateApr 30

Description

IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-jq56-hqwg-c6vv: IIS 32022-04-30
CVEList
CVE-1999-0253: IIS 32000-02-04
CVE-1999-0253 (HIGH CVSS 7.5) | IIS 3.0 with the iis-fix hotfix ins | cvebase.io