Description
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/8098
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-058
Vendor Advisory vendor-advisory
x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ238606
Scores
EPSS
0.3485
EPSS Percentile
98.3%
Details
Status
published
Products (3)
microsoft/internet_information_server
4.0
microsoft/site_server
3.0
microsoft/site_server_commerce
3.0
Published
Dec 21, 1999
Tracked Since
Feb 18, 2026