Information Disclosure Vulnerability in Microsoft Index Server 2.0
CVE-2001-0986

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 September 2001

Summary

The SQLQHit.asp sample file in Microsoft Index Server 2.0 is susceptible to an information disclosure vulnerability. This flaw allows unauthorized remote attackers to exploit the application by invoking sqlqhit.asp with specific CiScope parameter values. By doing so, attackers can gain access to sensitive data, including the physical file paths, file attributes, and sections of the source code, which can lead to further exploitation of the server's configuration and data.

References

EPSS Score

74% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.