Vulnerability Details CVE-2001-0986
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.741
EPSS Ranking 98.7%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2001-0986
-
cpe:2.3:a:microsoft:index_server:2.0