Record summary

CVE-1999-0278 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBMicrosoft IIS 3.0/4.0 / Microsoft Personal Web Server 2.0/3.0/4.0 - ASP Alternate Data StreamsExploitDB exploitby Paul AshtonNot analyzed1 file
ExploitDB

PoC details

References

3