Description In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. Remediation References CVE-1999-0278 Related Vulnerabilities WordPress Plugin Ninja Popups Multiple Vulnerabilities (4.5.3) XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29214) MODX Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-10382) Drupal Core 5.x Cross-Site Scripting (5.0 - 5.5) Dotclear Other Vulnerability (CVE-2006-3938) Severity Medium Classification CVE-1999-0278 Tags Missing Update Known Vulnerabilities