CVE-2001-0986
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 48.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 48.16% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/index server
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/214217Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3339Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7125
- http://www.securityfocus.com/archive/1/214217Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3339Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7125
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.