Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.
No PoCs from references.
- https://github.com/arunthunderfrost27/CVE-Analayser
- https://github.com/arunthunderfrost27/cve_analyzer