CVE-1999-0253

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Jan 1, 1997
Updated: Nov 20, 2024

Summary

CVE-1999-0253 is a vulnerability affecting Microsoft's Internet Information Services (IIS) version 3.0 with the iis-fix hotfix installed. Malicious actors can exploit this issue by utilizing a %2e in a URL instead of a dot, allowing them to gain unauthorized access to the source code of Active Server Pages (ASP) programs. This vulnerability poses a significant risk as the exposed source code can reveal sensitive information, potentially leading to further security breaches. To mitigate this issue, it is strongly recommended that affected systems be updated to a newer version of IIS or IIS 3.0 without the iis-fix hotfix.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share