Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.767
EPSS Ranking 98.9%