← All CVEs

CVE-2001-0986

medium · 5

SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.

5
CVSS
48.2%
EPSS (exploit prob.)
99th
EPSS percentile
2001-09-14
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

VendorProductAffected versions
microsoftindex_server2.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2001-0986