Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-1999-0278

EPSS 76.39% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-1999-0278

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft IIS 3.0/4.0 ::$DATA请求泄露ASP源代码漏洞(MS98-003)
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IIS是一款Windows NT系统自带的的Web服务器软件,由Microsoft公司开发维护。 IIS实现上存在一个问题,对于一个访问ASP文件的NTFS流的HTTP请求会直接返回ASP源代码,远程攻击者可以借此漏洞获取ASP页面的源代码而不是经过服务器解释执行后的页面。 IIS在处理文件请求时会先判断文件扩展名是否在可执行文件扩展名列表中,如果在,则执行并返回结果,如果不在,则直接返回文件内容。NTFS文件系统支持在文件中包含额外的数据流。$DATA是在NTFS文件系统中存储数据流的属性。当我们对一个
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-1999-0278

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-1999-0278

登录查看更多情报信息。

Same Patch Batch · n/a · 1999-09-29 · 320 CVEs total

CVE-1999-0312HP ypbind NIS 安全漏洞
CVE-1999-0326HP-UX mediainit程序漏洞
CVE-1999-0325HP-UX vhe_u_mnt创建根文件漏洞
CVE-1999-0324HP-UX ppl权限许可和访问控制漏洞
CVE-1999-0321Solaris kcms_configure 安全漏洞
CVE-1999-0320SunOS rpc.cmsd漏洞
CVE-1999-0316Linux splitvt 安全漏洞
CVE-1999-0315Solaris fdformat命令行缓冲区溢出漏洞
CVE-1999-0314IRIX ioconfig漏洞
CVE-1999-0313IRIX disk_bandwidth漏洞
CVE-1999-0305BSD 系统配置控件伪造连接漏洞
CVE-1999-0300Solaris NIS+ nis_cachemgr恶意服务器添加漏洞
CVE-1999-0301SunOS/Solaris ps缓冲区溢出漏洞
CVE-1999-0302SunOS/Solaris FTP客户端命令任意执行漏洞
CVE-1999-0303BNU UUCP安全漏洞
CVE-1999-0309HP-UX vgdisplay程序权限许可和访问控制漏洞
CVE-1999-0311HP-UX fpkg2swpk权限许可和访问控制漏洞
CVE-1999-0310HP-UX SSH 安全漏洞
CVE-1999-0327SGI syserr文件损毁漏洞
CVE-1999-0308HP-UX gwind信息修改漏洞

Showing top 20 of 320 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-1999-0278

No comments yet


Leave a comment