Information Disclosure Vulnerability in Microsoft Index Server 2.0
CVE-2001-0986
Currently unrated
Summary
The SQLQHit.asp sample file in Microsoft Index Server 2.0 is susceptible to an information disclosure vulnerability. This flaw allows unauthorized remote attackers to exploit the application by invoking sqlqhit.asp with specific CiScope parameter values. By doing so, attackers can gain access to sensitive data, including the physical file paths, file attributes, and sections of the source code, which can lead to further exploitation of the server's configuration and data.
References
EPSS Score
74% chance of being exploited in the next 30 days.
Timeline
Vulnerability Reserved
Vulnerability published