CVE-1999-0253
CVSS 2.0 Score 7.5 of 10 (high)
Details
Summary
CVE-1999-0253 is a vulnerability affecting Microsoft's Internet Information Services (IIS) version 3.0 with the iis-fix hotfix installed. Malicious actors can exploit this issue by utilizing a %2e in a URL instead of a dot, allowing them to gain unauthorized access to the source code of Active Server Pages (ASP) programs. This vulnerability poses a significant risk as the exposed source code can reveal sensitive information, potentially leading to further security breaches. To mitigate this issue, it is strongly recommended that affected systems be updated to a newer version of IIS or IIS 3.0 without the iis-fix hotfix.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft IIS
Affected Vendors
- Microsoft