Description
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
Affected products
- microsoft / internet_information_server3.0 – 3.0
- microsoft / internet_information_server4.0 – 4.0
- microsoft / windows_nt4.0 – 4.0
Exploits & proofs of concept
- exploit-dbMicrosoft IIS 3.0/4.0 / Microsoft Personal Web Server 2.0/3.0/4.0 - ASP Alternate Data Streamsby Paul Ashton
Updated 38m ago · 8 sources